Vulnerability Database

309,364

Total vulnerabilities in the database

CVE-2025-28972

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Suhas Surse WP Employee Attendance System allows Blind SQL Injection. This issue affects WP Employee Attendance System: from n/a through 3.5.

  • Published: Jun 17, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-28972
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.6
  • AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

CWEs:

OWASP TOP 10: