VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

812 CVEsRSS

CVE-2026-72807High· 8.0
3w ago

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
CVE-2026-14828High· 8.8
3w ago

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

▾ TwilightEPSS 1.4%via NVD
CVE-2026-59834High· 7.5
3w ago

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
CVE-2026-84208High· 7.5
3w ago

AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints

AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries …

▾ TwilightEPSS 0.46%via NVD
CVE-2026-75132Medium· 6.5
3w ago

WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint

WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint. A remote authenticated user with read-only privileges can inject arbitrary PostgreSQL exp…

▾ SunlitEPSS 0.49%via NVD
CVE-2026-82655High· 7.5
4w ago

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries

Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by provi…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-82545Medium· 6.3
4w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82541Medium· 6.3
4w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. The manipulation of the argument ID results in sql injection.…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82540Medium· 6.3
4w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82485Medium· 6.3
4w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The a…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82484Medium· 6.3
4w ago

A flaw has been found in itsourcecode Sales and Inventory System 1.0

A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82424Medium· 6.3
4w ago

A weakness has been identified in PHPGurukul Student Information System 1.0

A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-82422Medium· 6.3
4w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql injection. The attack may be launched …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82421Medium· 6.3
4w ago

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The attack may be init…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-80488Medium· 4.1
4w ago

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection att…

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection att…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-16061High· 8.6
4w ago

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

▾ TwilightEPSS 0.28%via NVD
CVE-2026-55855Medium· 6.5
1mo ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer param…

▾ Sunlitmariadb · mariadbEPSS 0.47%via NVD
CVE-2026-55208High· 7.7
1mo ago

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

▾ Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.41%via GHSA
CVE-2026-55634Critical· 9.9
1mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…

▾ Midnightpimcore · pimcore/pimcoreEPSS 0.65%via NVD
CVE-2026-55509High
1mo ago

WsgiDAV MySQL provider has a blind SQL injection

WsgiDAV MySQL provider has a blind SQL injection

▾ Twilightwsgidav · wsgidavEPSS 0.54%via OSV
CVE-2026-81728High· 8.1
1mo ago

Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that…

▾ TwilightDolibarr · dolibarrEPSS 0.44%via CVEORG
CVE-2026-37009Medium· 6.5
1mo ago

A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument.

A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument.

▾ SunlitEPSS 0.35%via NVD
CVE-2026-74820None
1mo ago

ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform

ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against …

▾ SunlitEPSS 0.42%via NVD
CVE-2026-81203High· 7.3
1mo ago

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is pos…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-54245High
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a dat…

▾ Twilightfleetdm · github.com/fleetdm/fleetEPSS 0.57%via NVD
CVE-2026-32593Medium· 5.9
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configur…

▾ Sunlitwinter · winter/wn-backend-moduleEPSS 0.27%via NVD
CVE-2026-46370Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege O…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.37%via NVD
CVE-2026-46371Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-pri…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.37%via NVD
CVE-2026-79804High· 7.3
1mo ago

A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5

A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument se…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-32551Critical· 9.3
1mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essential allows SQL Injection. This issue affects Woo Essential: from n/a through 4.3.0.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essential allows SQL Injection. This issue affects Woo Essential: from n/a through 4.3.0.

▾ MidnightDiviNext · Woo EssentialEPSS 0.40%via NVD
CWE-89 vulnerabilities (CVEs) — page 14 · VulnSea