Tag

#SQL Injection

12 stories taggedSQL Injection.

Full-frame edge-to-edge photoreal editorial image of a dimly lit server room with a single rack bathed in blue and red light, a laptop open on a nearby cart sho
Vulnerabilities

WordPress backup plugin hole leaves 3.25 million sites open to hijack

A flaw in All-in-One WP Migration and Backup lets unauthenticated attackers plant SQL that fires when an admin restores a backup, handing over full control of the site.

4 min read
Photoreal news-editorial shot of a stack of rack-mounted network appliances in a dim server room, faint amber status LEDs reflecting off polished floor tiles, s
Vulnerabilities

Hackers Are Breaking Into Switchvox Phone Systems Through a Critical Flaw

A severe bug in Sangoma's business phone platform lets attackers run code on servers without a password. Exploitation is already happening.

4 min read
Photoreal news-editorial shot of a dimly lit enterprise telecom server rack with VoIP gateway hardware and blinking amber status LEDs, blue-green ambient light
Vulnerabilities

Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software

Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

3 min read
A visual representation of a digital storm hitting a Drupal logo, symbolizing a security vulnerability
Vulnerabilities

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer

A newly public security hole in popular mapping software is drawing hundreds of attack attempts within hours. No fix exists yet.

3 min read
A close-up photorealistic view of a fractured dark blue computer chip on a black reflective surface, with hairline cracks glowing faint red from underneath, sha
Vulnerabilities

Metabase Zero-Day Turns Dashboards Into Data Heists at Framework and Tally

A critical flaw in the popular analytics tool let attackers walk in as admin. Customer names, emails and password hashes were taken before anyone knew the hole existed.

4 min read
Full-frame photoreal editorial image of a dimly lit server room in an Israeli office building, blue and amber indicator lights reflecting on polished floor, a f
Threat Intelligence

Hackers hid their attack tools inside an Oracle database itself

A rarely seen technique let intruders run commands, steal password data and browse files from within the database, after breaking in through a sloppy search box.

4 min read
A glowing red countdown timer overlaid on a rack of web hosting servers in a dark data center, lighting, shallow depth of field, sense of urgency
Vulnerabilities

cPanel patches critical database flaw that let hosting customers run SQL as root

A newly disclosed bug, CVE-2026-58048, crossed the line between a single hosting account and the server's master database identity. cPanel has shipped a targeted fix.

3 min read
A close-up, macro, photoreal, news-editorial shot of a tangled cluster of worn ethernet and USB cables plugged into a dusty server strip, bathed in the cool blu
Vulnerabilities

WP2Shell: Two WordPress Flaws Let Attackers Take Over Websites Without Logging In

Criminals are actively exploiting a pair of newly discovered security holes in WordPress to seize full control of websites. Tens of millions of sites were at risk, and patching may already be too late for some.

3 min read
Macro photograph of tangled fiber optic cables glowing in deep blue and green light against a dark server room background, sharp focus on the glass fiber tips w
Vulnerabilities

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk

A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

3 min read
AI Security

LangGraph Patches Three Bugs, Including an SQLi-to-RCE Chain in Self-Hosted Agents

The framework underpinning a wave of multi-agent AI deployments shipped fixes for a flaw chain that let attackers pivot from SQL injection to code execution on self-hosted nodes.

3 min read
Vulnerabilities

CISA Flags Exploited Drupal SQL Injection Flaw. Drupal Won't Say Who Got Hit.

CVE-2026-9082 is in the Known Exploited Vulnerabilities catalog. The advisory mentions active exploitation. It does not mention victims, telemetry, or how anyone found out.

2 min read
Vulnerabilities

A SQL Bug in a Blogging Tool Just Became a ClickFix Delivery Truck

Attackers turned 700+ Ghost CMS sites into watering holes by exploiting CVE-2026-26980, smuggling fake CAPTCHA prompts that trick visitors into running malware on themselves.

2 min read
© 2026 Threat Vectr