CWE-89
CVEs classified under CWE-89, newest first.
811 CVEsRSS
CVE-2026-86245Medium· 6.3PoCA vulnerability was detected in itsourcecode Sales and Inventory System 1.0
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in …
CVE-2026-86236Medium· 6.3PoCA vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argument Name leads to sql injection. The a…
CVE-2026-86235Medium· 6.3PoCA flaw has been found in itsourcecode Sales and Inventory System 1.0
A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer causes sql injection. The attack can …
CVE-2026-86234Medium· 6.3PoCA vulnerability was detected in itsourcecode Sales and Inventory System 1.0
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible…
CVE-2026-86233Medium· 6.3PoCA security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql inj…
CVE-2026-86232Medium· 6.3PoCA weakness has been identified in itsourcecode Sales and Inventory System 1.0
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argument ID can lead …
CVE-2026-86225High· 7.3PoCA vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads t…
CVE-2026-86224High· 7.3PoCA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql inject…
CVE-2026-86223High· 7.3PoCA vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection…
CVE-2026-86222High· 7.3PoCA vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection. The…
CVE-2026-86221High· 7.3PoCA flaw has been found in SourceCodester Class and Exam Timetabling System 1.0
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection. The…
CVE-2026-86220High· 7.3PoCA vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injec…
CVE-2026-19634Medium· 6.4PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions
PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() o…
CVE-2026-19633High· 8.8PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in t…
CVE-2026-86213High· 7.3PoCA vulnerability was found in Mstfakts College-Management-System
A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author re…
CVE-2026-86211High· 7.3PoCA flaw has been found in rabindralamsal inventory-management-system 1.0.0
A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. T…
CVE-2026-86210High· 7.3PoCA security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID lea…
CVE-2026-86209High· 7.3PoCA weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated …
CVE-2026-86208High· 7.3PoCA security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can b…
CVE-2026-86180High· 7.3PoCA vulnerability has been found in code-projects Task Management System In PHP 1.0
A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to …
CVE-2026-86172Medium· 6.3PoCA vulnerability was detected in DefaultFuction CRM 1.0.0
A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the a…
CVE-2026-86171Medium· 6.3PoCA security vulnerability has been detected in DefaultFuction CRM 1.0.0
A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed fro…
CVE-2026-86170Medium· 6.3PoCA weakness has been identified in DefaultFuction CRM 1.0.0
A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried…
CVE-2026-86168High· 7.3PoCA security flaw has been discovered in code-projects Content Management System 1.0
A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can b…
CVE-2026-86164Medium· 6.3PoCA security flaw has been discovered in itsourcecode Sales and Inventory System 1.0
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in sql injection. The attack may be perfor…
CVE-2026-86163Medium· 6.3PoCA vulnerability was identified in itsourcecode Sales and Inventory System 1.0
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carr…
CVE-2026-86162High· 7.3PoCA vulnerability was determined in SourceCodester Online Voting System 1.0
A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can b…
CVE-2026-86161High· 7.3PoCA vulnerability was found in SourceCodester Online Voting System 1.0
A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote…
CVE-2026-86160High· 7.3PoCA vulnerability has been found in SourceCodester Online Voting System 1.0
A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack ma…
CVE-2026-86159High· 7.3PoCA flaw has been found in SourceCodester Online Voting System 1.0
A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. Th…