We have discovered 2,578,088 live websites that are affected by CWE-89.
![]() | 648,424 websites |
![]() | 268,312 websites |
![]() | 195,796 websites |
![]() | 156,533 websites |
![]() | 154,219 websites |
![]() | 111,798 websites |
![]() | 90,837 websites |
![]() | 85,433 websites |
![]() | 68,429 websites |
![]() | 59,764 websites |
.com | 990,747 websites |
.de | 130,056 websites |
.it | 109,815 websites |
.org | 106,629 websites |
.ru | 96,429 websites |
.net | 75,070 websites |
.pl | 67,313 websites |
.nl | 59,429 websites |
.co.uk | 59,293 websites |
.fr | 55,425 websites |
Discovered | CVE | Description | Websites |
---|---|---|---|
Apr, 2025 | CVE-2025-2128 | Cost Calculator Builder <= 3.2.67 - Authenticated (Subscriber+) SQL Injection via order_ids Parameter | 909 |
Apr, 2025 | CVE-2025-31565 | WordPress WPSmartContracts plugin <= 2.0.10 - SQL Injection vulnerability | 1 |
Apr, 2025 | CVE-2025-32565 | WordPress Neon Product Designer Plugin <= 2.1.1 - Unauthenticated SQL Injection vulnerability | 8 |
Apr, 2025 | CVE-2025-32603 | WordPress WP Online Users Stats plugin <= 1.0.0 - SQL Injection vulnerability | 7 |
Apr, 2025 | CVE-2025-32618 | WordPress Wishlist plugin <= 1.0.43 - SQL Injection vulnerability | 1 |
Apr, 2025 | CVE-2025-32650 | WordPress Accessibility Suite by Ability, Inc plugin <= 4.18 - SQL Injection vulnerability | 39 |
Apr, 2025 | CVE-2025-32128 | WordPress Nearby Locations Plugin <= 1.1.1 - SQL Injection vulnerability | 17 |
Apr, 2025 | CVE-2025-32687 | WordPress Review Stars Count For WooCommerce <= 2.0 - SQL Injection Vulnerability | 1 |
Apr, 2025 | CVE-2025-32676 | WordPress Verowa Connect plugin <= 3.0.5 - SQL Injection vulnerability | 63 |
Apr, 2025 | CVE-2025-32677 | WordPress WP Social Stream Designer plugin <= 1.3 - SQL Injection vulnerability | 24 |
Discovered | CVE | Description | Websites |
---|---|---|---|
Jan, 2022 | CVE-2022-21661 | SQL injection in WordPress | 1,884,492 |
Jan, 2022 | CVE-2022-21664 | SQL injection in WordPress | 1,562,406 |
May, 2023 | CVE-2023-0329 | Elementor Website Builder < 3.12.2 - Admin+ SQLi | 468,834 |
Sep, 2024 | CVE-2024-8275 | The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection | 47,634 |
Mar, 2023 | CVE-2023-0955 | WP Statistics < 14.0 - Authenticated SQLi | 38,788 |
Mar, 2023 | CVE-2022-38074 | WordPress WP Statistics Plugin <= 13.2.10 is vulnerable to SQL Injection | 35,298 |
Jan, 2023 | CVE-2022-4230 | WP Statistics < 13.2.9 - Authenticated SQLi | 34,775 |
Mar, 2025 | CVE-2025-1702 | Ultimate Member <= 2.10.0 - Unauthenticated SQL Injection via search Parameter | 33,360 |
Feb, 2025 | CVE-2024-12276 | Ultimate Member <= 2.9.2 - Authenticated SQL Injection | 31,481 |
Feb, 2025 | CVE-2024-11260 | Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter | 24,337 |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.org | ![]() | *** | |
****.br | ![]() | *** | |
********.com | ![]() | *** | |
****.******.com | ![]() | *** | |
*********.com | ![]() | *** | |
*********.net | ![]() | *** | |
************.***.ar | ![]() | *,*** | |
****.*******.org | ![]() | *,*** | |
********.com | ![]() | *,*** | |
***************.eu | ![]() | *,*** |