CVE-2026-42415 — Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
Cybersecurity watch: alerts, vulnerabilities, news and tools to protect yourself.
Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions.
Subscriber SQL Injection in ListingPro <= 2.9.12 versions.
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions.
Subscriber SQL Injection in Woffice <= 5.4.35 versions.
Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions.
Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.
Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions.
Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions.