VYPR

Library Management System

by WordPress

Source repositories

CVEs (7)

  • CVE-2025-12707HigFeb 19, 2026
    risk 0.49cvss 7.5epss 0.00

    The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2024-8679MedDec 7, 2024
    risk 0.37cvss 6.8epss 0.00

    The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied…

  • CVE-2024-12406MedDec 12, 2024
    risk 0.35cvss 6.5epss 0.00

    The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2026-18666MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including…

  • CVE-2025-10303MedOct 15, 2025
    risk 0.21cvss 4.3epss 0.00

    The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated…

  • CVE-2026-12582HigJul 13, 2026
    risk 0.00cvss 8.6epss 0.00

    The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user…

  • CVE-2026-56034CriJun 26, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.