VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

811 CVEsRSS

CVE-2026-78623High· 7.7
2w ago

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to …

▾ Twilightokta · access_gatewayEPSS 0.45%via NVD
CVE-2026-75746Critical· 9.1
2w ago

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privi…

▾ Midnightadobe · coldfusionEPSS 0.99%via NVD
CVE-2026-86675Medium· 6.3PoC
2w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely.…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-69716High· 8.8
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · sharepoint_serverEPSS 0.99%via NVD
CVE-2026-69636Medium· 6.5
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · sharepoint_serverEPSS 1.00%via NVD
CVE-2026-67370High· 8.8
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.99%via NVD
CVE-2026-66820High· 8.8
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.99%via NVD
CVE-2026-66819High· 8.8
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · sql_server_2017EPSS 0.99%via NVD
CVE-2026-62895High· 8.8
2w ago

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure Arc SQL Server ExtensionEPSS 0.82%via NVD
CVE-2026-86667Medium· 4.7PoC
2w ago

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search causes sql injection. The attack is possi…

▾ Twilightaircheng-org · iWebShop-5EPSS 0.35%via NVD
CVE-2026-79570Critical· 9.8PoC
2w ago

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

▾ AbyssalEPSS 0.47%via NVD
CVE-2026-79569Critical· 9.8PoC
2w ago

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

▾ AbyssalEPSS 0.47%via NVD
CVE-2026-79573Medium· 6.5
2w ago

L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters

L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database i…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-78837High· 7.5PoC
2w ago

A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.

A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.

▾ MidnightEPSS 0.43%via NVD
CVE-2026-77098Critical· 9.8
2w ago

Private Metrics Server contained an SQL injection condition affecting database operations

Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

▾ Midnightcommvault · commvaultEPSS 0.47%via NVD
CVE-2026-17509Medium· 6.5
2w ago

The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of s…

The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 due to insufficient escaping on the user supplied parameter and lack of s…

▾ SunlitWPML · WPML Multilingual CMSEPSS 0.23%via NVD
CVE-2026-86518Medium· 6.3PoC
2w ago

A vulnerability has been found in code-projects Student Crud Operation 1.0

A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exp…

▾ Twilightcode-projects · Student Crud OperationEPSS 0.33%via NVD
CVE-2026-86517Medium· 6.3PoC
2w ago

A flaw has been found in itsourcecode Sales and Inventory System 1.0

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is pos…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-44766Medium· 6.5
2w ago

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the us…

▾ SunlitSAP_SE · SAP S/4HANA (Intercompany Matching and Reconciliation)EPSS 0.39%via NVD
CVE-2026-86310Medium· 6.3PoC
2w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be …

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86309Medium· 6.3PoC
2w ago

A flaw has been found in itsourcecode Sales and Inventory System 1.0

A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. …

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86298High· 7.3PoC
2w ago

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is po…

▾ MidnightSourceCodester · Class and Exam Timetabling SystemEPSS 0.43%via NVD
CVE-2026-86291Medium· 6.3PoC
2w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be l…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86290High· 7.3PoC
2w ago

A weakness has been identified in SourceCodester Online Voting System 1.0

A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack ca…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-86282High· 7.3PoC
2w ago

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the compo…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.45%via NVD
CVE-2026-86270Medium· 6.3PoC
2w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may …

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86269Medium· 6.3PoC
2w ago

A flaw has been found in itsourcecode Sales and Inventory System 1.0

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be c…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-86268High· 7.3PoC
2w ago

A vulnerability was detected in itsourcecode School Management System 1.0

A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. …

▾ Midnightitsourcecode · School Management SystemEPSS 0.43%via NVD
CVE-2026-86267Medium· 6.3PoC
2w ago

A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0

A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id l…

▾ Twilightitsourcecode · Information System Society Membership SystemEPSS 0.33%via NVD
CVE-2026-86265Medium· 6.3PoC
2w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such manipulation of the argument Username leads to sql injectio…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CWE-89 vulnerabilities (CVEs) — page 11 · VulnSea