SQL Injection
Injection flaws in database query construction, with the reachable sink and the payload that proves it.
Published work on this topic
| 2026-08-11 | CVE-2026-72899 | CVE-2026-72899: Metabase Unauthenticated SQL Injection | PoC | |
| 2026-08-11 | CVE-2026-72898 | CVE-2026-72898: Metabase SQL Injection - Admin Takeover | PoC | |
| 2026-08-04 | CVE-2026-42208 | CVE-2026-42208: LiteLLM Pre-Auth SQL Injection | PoC | |
| 2026-08-04 | CVE-2026-9082 | CVE-2026-9082: Drupal SQL Injection | PoC | |
| 2026-07-24 | CVE-2026-63030 | CVE-2026-63030: WordPress wp2shell Pre-Auth RCE | PoC |
