
sqlancer
Automated testing to find logic and performance bugs in database systems

Automated testing to find logic and performance bugs in database systems

Proof-of-concept payloads and annotated HTTP request for blind SQL injection in TripSpark VEO Transportation. Demonstrates out-of-band exploitation…

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

Proof-of-concept for CVE-2025-25964, a critical SQL injection in School Information Management System v1.0, with reproduction steps and SQLMap…

Educational analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362), detailing unauthenticated SQL injection exploitation and its global…

Proof-of-concept exploit for CVE-2025-67644, a SQL injection vulnerability in LangGraph SQLite Checkpoint. Demonstrates arbitrary SQL injection via…

Detailed analysis of CVE-2022-33171, a SQL injection vulnerability in TypeORM's findOne() functions, including root cause, impact, and mitigation…

Detailed analysis of CVE-2025-7461, a SQL injection vulnerability in Modern Bag E-commerce System, including root cause, affected code, and…

Proof-of-concept and technical write-up for CVE-2026-65971 — SQL injection via the sortDirection Livewire property in…

Proof-of-concept exploit for CVE-2026-33910, an authenticated SQL injection vulnerability in OpenEMR <8.0.0.3, with detailed analysis, PoC code, and…

Documented CVE-2026-24419: SQL injection vulnerability in OpenSTAManager Prima Nota module with PoC, root cause analysis, and recommended fix for…

Proof-of-concept exploit for CVE-2025-52399, demonstrating SQL injection in the loginlinkfaculty endpoint of Institute-of-Current-Students, enabling…

Proof-of-concept and technical walkthrough for CVE-2025-9776, an authenticated SQL injection in the CatFolders WordPress plugin via CSV import,…

Educational analysis of CVE-2023-24203 (Stored XSS) and CVE-2023-24204 (SQL Injection) in SourceCodester CRM, with exploitation steps and mitigation…

Proof-of-concept for CVE-2026-63039, demonstrating ORDER BY SQL injection in Apache InLong's AuditAlertRule via orderField/orderType, with a…

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.