Library Management System
Library Management System: vulnerabilidades y CVE
Library Management System tiene 5 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-18666 | Media (4.3) | 0.27% | — | 10 ago 2026 | The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL… |
| CVE-2026-12582 | Alta (8.6) | 0.45% | — | 13 jul 2026 | The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and… |
| CVE-2026-56034 | Crítica (9.3) | 0.40% | — | 26 jun 2026 | Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. |
| CVE-2025-12707 | Alta (7.5) | 0.45% | — | 19 feb 2026 | The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack… |
| CVE-2025-10303 | Media (4.3) | 0.23% | — | 15 oct 2025 | The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.