Library Management System
by WordPress
Source repositories
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-12707 | Hig | 0.49 | 7.5 | 0.00 | Feb 19, 2026 | The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | ||
| CVE-2024-8679 | Med | 0.37 | 6.8 | 0.00 | Dec 7, 2024 | The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied… | ||
| CVE-2024-12406 | Med | 0.35 | 6.5 | 0.00 | Dec 12, 2024 | The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of… | ||
| CVE-2026-18666 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2026 | The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including… | ||
| CVE-2025-10303 | Med | 0.21 | 4.3 | 0.00 | Oct 15, 2025 | The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated… | ||
| CVE-2026-12582 | Hig | 0.00 | 8.6 | 0.00 | Jul 13, 2026 | The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user… | ||
| CVE-2026-56034 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. |
- risk 0.49cvss 7.5epss 0.00
The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
- risk 0.37cvss 6.8epss 0.00
The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied…
- risk 0.35cvss 6.5epss 0.00
The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the 'owt7_borrow_books_id' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of…
- risk 0.28cvss 4.3epss 0.00
The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including…
- risk 0.21cvss 4.3epss 0.00
The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the owt7_library_management_ajax_handler() function in all versions up to, and including, 3.1. This makes it possible for authenticated…
- risk 0.00cvss 8.6epss 0.00
The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user…
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.