VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

811 CVEsRSS

CVE-2026-15439Medium· 6.5
2w ago

GamiPress <= 7.9.7 - Authenticated (Subscriber+) SQL Injection

The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (action gamipress_wpforo_get_posts) in versions up to, and including, 7.9.7. The …

▾ Sunlitrubengc · GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AIEPSS 0.23%via CVEORG
CVE-2026-62112High· 7.6
2w ago

WordPress Amelia plugin <= 2.4.9 - SQL Injection vulnerability

Editor SQL Injection in Amelia <= 2.4.9 versions.

▾ TwilightMelograno Venture Studio · ameliabookingEPSS 0.38%via CVEORG
CVE-2026-82583High· 8.3
2w ago

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary fil…

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary fil…

▾ TwilightNextGen Healthcare · Mirth ConnectEPSS 0.45%via NVD
CVE-2026-15462High· 7.5
2w ago

The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2

The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data(…

▾ Twilightgingerplugins · Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message ButtonsEPSS 0.30%via NVD
CVE-2026-88890High· 8.5
2w ago

OpenPanel SQL Injection via unvalidated profile filter column identifier

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.39%via CVEORG
CVE-2026-81800Critical· 9.3
2w ago

WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability

Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

▾ MidnightPar avisverifies · netreviewsEPSS 0.40%via CVEORG
CVE-2026-89089Medium· 6.5
2w ago

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports "…

▾ SunlitThe OpenNMS Group · MeridianEPSS 0.36%via NVD
CVE-2026-87925High· 7.3PoC
2w ago

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipula…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.43%via NVD
CVE-2026-78082Critical· 9.3
2w ago

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting…

▾ Midnightjoomshaper.com · SP Property extension for JoomlaEPSS 0.51%via CVEORG
CVE-2026-73698High· 7.2PoC
2w ago

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

▾ MidnightFileRun · FileRunEPSS 0.62%via NVD
CVE-2026-38626Critical· 9.8
2w ago

Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

▾ MidnightEPSS 0.47%via NVD
CVE-2026-9163Critical· 9.8
2w ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from…

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from…

▾ MidnightGIS Informatics · GisLab Laboratory Management SystemEPSS 0.47%via NVD
CVE-2026-7188Critical· 9.8
2w ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before …

▾ MidnightArmiya Information Technologies Ltd. Co. · Access Control SystemEPSS 0.47%via NVD
CVE-2026-79387Medium· 4.3PoC
2w ago

SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account …

SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account …

▾ TwilightEPSS 0.29%via NVD
CVE-2026-87807High· 7.5
2w ago

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing pu…

▾ Twilightsiyuan-note · siyuanEPSS 0.45%via NVD
CVE-2026-79947Medium· 5.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

▾ Sunlitdell · secure_connect_gatewayEPSS 1.8%via NVD
CVE-2026-78482Medium· 5.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

▾ Sunlitdell · secure_connect_gatewayEPSS 2.5%via NVD
CVE-2026-67401Critical· 9.9PoC
2w ago

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

▾ AbyssalWebPros · cPanelEPSS 0.86%via NVD
CVE-2026-79972High· 7.2
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privile…

▾ TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.45%via CVEORG
CVE-2026-87921High· 7.3PoC
2w ago

A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_catego…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.43%via NVD
CVE-2026-79322High· 8.6
2w ago

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents v…

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents v…

▾ Twilightmageplaza · mageplaza_blogEPSS 0.47%via NVD
CVE-2026-79640Medium· 5.4
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileg…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.25%via NVD
CVE-2026-19778Medium· 6.5
2w ago

The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insuffic…

The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insuffic…

▾ Sunlitaukejomm · WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & ShoppingEPSS 0.26%via NVD
CVE-2026-80177Medium· 6.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileg…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.37%via NVD
CVE-2026-84113Medium· 4.1
2w ago

The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL query, allowing high privilege users such as administrators to perform SQL injection attacks.

The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL query, allowing high privilege users such as administrators to perform SQL injection attacks.

▾ SunlitEPSS 0.31%via NVD
CVE-2026-84068High· 8.6
2w ago

The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection.

The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection.

▾ TwilightEPSS 0.45%via NVD
CVE-2026-14962High· 8.6PoC
2w ago

The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary da…

The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary da…

▾ MidnightEPSS 0.40%via NVD
CVE-2026-19944Medium· 4.9
2w ago

The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient p…

The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient p…

▾ Sunlitthemeum · WP CrowdfundingEPSS 0.26%via NVD
CVE-2026-19800Medium· 4.9
2w ago

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping o…

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping o…

▾ Sunlitgetwpfunnels · Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce EmailsEPSS 0.31%via NVD
CVE-2026-87034High· 8.3
2w ago

Tanium addressed a SQL injection vulnerability in Comply.

Tanium addressed a SQL injection vulnerability in Comply.

▾ Twilighttanium · complyEPSS 0.33%via NVD
CWE-89 vulnerabilities (CVEs) — page 10 · VulnSea