VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

812 CVEsRSS

CVE-2026-86159High· 7.3PoC
3w ago

A flaw has been found in SourceCodester Online Voting System 1.0

A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. Th…

▾ MidnightSourceCodester · Online Voting SystemEPSS 0.43%via NVD
CVE-2026-84937Medium· 6.8
3w ago

The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks…

The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-84221Medium· 6.8
3w ago

The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, includin…

The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, includin…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-82304High· 8.6
3w ago

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

▾ TwilightEPSS 0.45%via NVD
CVE-2026-52763Medium· 6.5
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form against ['day','w…

▾ SunlitYesWiki · yeswikiEPSS 0.38%via NVD
CVE-2026-52770High· 7.5PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is nume…

▾ MidnightYesWiki · yeswikiEPSS 0.47%via NVD
CVE-2026-52771High· 8.3
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping.…

▾ TwilightYesWiki · yeswikiEPSS 0.51%via NVD
CVE-2026-52775High· 8.8PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject a…

▾ MidnightYesWiki · yeswikiEPSS 0.48%via NVD
CVE-2026-85516High· 7.3PoC
3w ago

code-projects Vehicle Management System busprofile.php sql injection

A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possibl…

▾ Midnightcode-projects · Vehicle Management SystemEPSS 0.43%via CVEORG
CVE-2026-85402High· 7.3PoC
3w ago

code-projects Doctor Appointment System booking.php sql injection

A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be la…

▾ Midnightcode-projects · Doctor Appointment SystemEPSS 0.43%via CVEORG
CVE-2026-85383Medium· 6.3PoC
3w ago

itsourcecode Sales and Inventory System inv_del.php sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be ex…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via CVEORG
CVE-2026-82538High· 8.8
3w ago

ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without …

ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without …

▾ TwilightILIAS-eLearning e.V. · ILIASEPSS 0.67%via NVD
CVE-2026-71622High· 7.4PoC
3w ago

SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component

SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component

▾ MidnightEPSS 0.45%via NVD
CVE-2026-85540High· 8.8
3w ago

DreamMaker developed by Interinfo has a SQL Injection vulnerability

DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

▾ TwilightEPSS 0.54%via NVD
CVE-2026-82186Medium· 4.1
3w ago

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator privileges to perform SQL injection attacks.

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator privileges to perform SQL injection attacks.

▾ SunlitEPSS 0.31%via NVD
CVE-2026-85689Medium· 6.5
3w ago

llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolated into SQL WHERE clauses without parameterization or escaping, in…

llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolated into SQL WHERE clauses without parameterization or escaping, in…

▾ Sunlitllmware-ai · llmwareEPSS 0.42%via NVD
CVE-2026-53756Medium· 4.9PoC
3w ago

Emlog is an open source website building system

Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filt…

▾ Twilightemlog · emlogEPSS 0.43%via NVD
CVE-2026-85643Medium· 4.7PoC
3w ago

A flaw has been found in code-projects Online Shopping System 1.0

A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performe…

▾ Twilightcode-projects · Online Shopping SystemEPSS 0.35%via NVD
CVE-2025-67066Critical· 9.8PoC
3w ago

SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path

SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path

▾ AbyssalEPSS 0.50%via NVD
CVE-2026-18658Critical· 9.8
3w ago

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to…

▾ MidnightIBM · Operational Decision ManagerEPSS 0.43%via NVD
CVE-2026-52691High· 8.8
3w ago

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.  This issue affects Apache Griffin Hive Metastore Module: all …

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.  This issue affects Apache Griffin Hive Metastore Module: all …

▾ TwilightApache Software Foundation · org.apache.griffin:serviceEPSS 0.46%via NVD
CVE-2026-18198High· 8.8
3w ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN O…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-85399High· 7.3PoC
3w ago

A security flaw has been discovered in code-projects Hospital Information System 1.0

A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument…

▾ Midnightcode-projects · Hospital Information SystemEPSS 0.43%via NVD
CVE-2026-82527High· 7.5
3w ago

R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter key parameter in the retrieval search endpoint

R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter key parameter in the retrieval search endpoint. Attackers can…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-85205Medium· 6.3
3w ago

A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0

A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argum…

▾ Sunlititsourcecode · Online Medicine Delivery SystemEPSS 0.33%via NVD
CVE-2026-85388High· 8.1
3w ago

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based …

▾ TwilightEPSS 0.48%via NVD
CVE-2026-82526Critical· 9.8
3w ago

R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint

R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is …

▾ MidnightEPSS 0.71%via NVD
CVE-2026-85155High· 7.5
3w ago

WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.passw…

WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.passw…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-85225High· 7.3
3w ago

A vulnerability was identified in code-projects Doctor Appointment System 1.0

A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initi…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-72811Critical· 10.0
3w ago

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.44%via GHSA
CWE-89 vulnerabilities (CVEs) — page 13 · VulnSea