SEKurity GmbH Logo
Home/Tags/SQL Injection

#SQL Injection

2 Articles tagged

[*] Filtering articles by tag: SQL Injection
[+] Matching entries: 2
root@sekurity:~# ls -la /tags/sql-injection/* _

CVE Research
sekurity-team

InSEKurity of the Week (CW30/2026): WordPress Core wp2shell Pre-Auth RCE (CVE-2026-63030 & CVE-2026-60137)

A REST API batch-route confusion in WordPress Core chained with a WP_Query SQL injection gives unauthenticated attackers remote code execution on a default WordPress install -- no plugins, no credentials, and it is already being exploited in the wild.

01
CVE Research
sekurity-team

InSEKurity of the Week (CW21/2026): Drupal Core Anonymous SQL Injection (CVE-2026-9082)

An unauthenticated SQL injection in Drupal core's PostgreSQL EntityQuery handler -- anonymous attackers turn JSON object keys and JSON:API filter parameters into raw SQL fragments. Drupal-rated 23/25 'Highly Critical', CISA KEV, 15,000+ exploit attempts in 48 hours

02

root@sekurity:~# echo "End of results for tag: SQL Injection"
End of results for tag: SQL Injection
root@sekurity:~# _