Vulnerability Database

322,905

Total vulnerabilities in the database

CVE-2021-47811

Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the order_by[] parameter in POST requests to the ajax_list endpoint to potentially extract or modify database information.

  • Published: Jan 16, 2026
  • Updated: Feb 3, 2026
  • CVE: CVE-2021-47811
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.1
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CWEs:

OWASP TOP 10: