#SQL Injection
12 stories taggedSQL Injection.

WordPress backup plugin hole leaves 3.25 million sites open to hijack
A flaw in All-in-One WP Migration and Backup lets unauthenticated attackers plant SQL that fires when an admin restores a backup, handing over full control of the site.

Hackers Are Breaking Into Switchvox Phone Systems Through a Critical Flaw
A severe bug in Sangoma's business phone platform lets attackers run code on servers without a password. Exploitation is already happening.

Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software
Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer
A newly public security hole in popular mapping software is drawing hundreds of attack attempts within hours. No fix exists yet.

Metabase Zero-Day Turns Dashboards Into Data Heists at Framework and Tally
A critical flaw in the popular analytics tool let attackers walk in as admin. Customer names, emails and password hashes were taken before anyone knew the hole existed.

Hackers hid their attack tools inside an Oracle database itself
A rarely seen technique let intruders run commands, steal password data and browse files from within the database, after breaking in through a sloppy search box.

cPanel patches critical database flaw that let hosting customers run SQL as root
A newly disclosed bug, CVE-2026-58048, crossed the line between a single hosting account and the server's master database identity. cPanel has shipped a targeted fix.

WP2Shell: Two WordPress Flaws Let Attackers Take Over Websites Without Logging In
Criminals are actively exploiting a pair of newly discovered security holes in WordPress to seize full control of websites. Tens of millions of sites were at risk, and patching may already be too late for some.

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk
A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

LangGraph Patches Three Bugs, Including an SQLi-to-RCE Chain in Self-Hosted Agents
The framework underpinning a wave of multi-agent AI deployments shipped fixes for a flaw chain that let attackers pivot from SQL injection to code execution on self-hosted nodes.

CISA Flags Exploited Drupal SQL Injection Flaw. Drupal Won't Say Who Got Hit.
CVE-2026-9082 is in the Known Exploited Vulnerabilities catalog. The advisory mentions active exploitation. It does not mention victims, telemetry, or how anyone found out.

A SQL Bug in a Blogging Tool Just Became a ClickFix Delivery Truck
Attackers turned 700+ Ghost CMS sites into watering holes by exploiting CVE-2026-26980, smuggling fake CAPTCHA prompts that trick visitors into running malware on themselves.