Vulnerabilities protected by our SQL Injection firewall rule

1,488,312
Attacks Blocked in Past 24 Hours

Showing 921-940 of 1,444 Vulnerabilities

Title CVE ID CVSS Vector Date
WordPress Core < 2.1.3 - SQL Injection CVE-2007-1897 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H April 3, 2007
WordPress Core < 2.0.7 - SQL Injection CVE-2007-0233 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H January 15, 2007
WordPress Core < 1.5.1.3 - SQL Injection CVE-2005-2108 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H June 29, 2005
WordPress Core < 1.5.1.2 - SQL Injection CVE-2005-1810 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H May 27, 2005
WordPress Core < 1.5.1 - SQL Injection CVE-2005-1687 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H May 9, 2005
WordPress Core < 0.72 - SQL Injection CVE-2003-1598 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H October 11, 2003
Relevanssi <= 3.6.0 - Authenticated (Admin+) SQL Injection 8.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N April 10, 2018
WP Statistics < 9.4.1 - Authenticated Blind SQL Injection 8.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N July 9, 2015
JS Help Desk <= 2.7.1 - Unauthenticated SQL Injection CVE-2022-47151 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N January 27, 2023
Hide My WP <= 6.2.3 - SQL Injection CVE-2021-36916 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L November 24, 2021
Formidable Form Builder < 2.05.03 - SQL Injection 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N November 13, 2017
Barcode Scanner with Inventory & Order Manager <= 1.6.1 - Authenticated (Subscriber+) SQL Injection CVE-2024-38708 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H July 11, 2024
Advanced Contact form 7 DB <= 1.6.0 - SQL Injection 8.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N April 11, 2019
Email Subscribers & Newsletters < 4.3.1 - Unauthenticated Blind SQL Injection CVE-2019-20361 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L November 13, 2019
bbPress < 2.5.13 - Unauthenticated Blind SQL Injection 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L November 13, 2017
NextGen Gallery <= 2.1.77 - SQL Injection 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L February 17, 2017
WP eCommerce < 3.11.4 - SQL Injection 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L November 12, 2016
GB Gallery Slideshow <= 1.5 - SQL Injection CVE-2014-8375 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L August 11, 2014
SP Rental Manager <= 1.5.3 - Unauthenticated SQL Injection CVE-2021-38324 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L September 8, 2021
Slimstat Analytics < 3.9.6 - Unauthenticated Blind SQL Injection 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N February 24, 2015

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation