VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

812 CVEsRSS

CVE-2026-77635CriticalPoC
1mo ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data i…

▾ Abyssalcakephp · cakephp/cakephpEPSS 0.49%via NVD
CVE-2026-76602None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.3 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

▾ SunlitEPSS 0.39%via NVD
CVE-2026-76571None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery…

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-76904Critical· 9.8PoC
1mo ago

GeoTools is an open source Java library that provides tools for geospatial data

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataS…

▾ Abyssalgeotools · org.geotools.jdbc:gt-jdbc-postgisEPSS 2.4%via NVD
CVE-2026-53572Medium· 5.9
1mo ago

KEDA is a Kubernetes-based Event Driven Autoscaling component

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values,…

▾ Sunlitkedacore · github.com/kedacore/keda/v2EPSS 0.39%via NVD
CVE-2026-46682High· 8.5
1mo ago

BigBlueButton is an open-source virtual classroom

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/mai…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-68789Critical· 9.9
1mo ago

Azure SQL Database Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure SQL DatabaseEPSS 0.99%via CVEORG
CVE-2026-68782Critical· 9.9
1mo ago

Azure SQL Database Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure SQL DatabaseEPSS 0.99%via CVEORG
GHSA-rxhg-vcww-2mpwLow· 3.1
1mo ago

Fleet: ORDER BY column injection on activity list endpoints

Fleet: ORDER BY column injection on activity list endpoints

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
CVE-2026-61518High· 8.8
1mo ago

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API

ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized …

▾ TwilightEPSS 0.46%via NVD
CVE-2026-49392Medium· 5.3
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file p…

▾ Sunlitwazuh · wazuhEPSS 0.30%via NVD
CVE-2026-51366Critical· 9.9
1mo ago

SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter

SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter

▾ MidnightEPSS 0.78%via NVD
CVE-2026-71867Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71866Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema w…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-76049High· 7.3
1mo ago

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is pos…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-76240High
1mo ago

stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting

stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a sc…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.38%via NVD
CVE-2026-54348High· 7.2
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it as JSON in panel_admins.i…

▾ Twilightfroxlor · froxlor/froxlorEPSS 0.66%via NVD
CVE-2026-47720Medium· 5.3
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString function in server/runtime/storage/tdengine/index.js doubles single quotes but does not escape …

▾ Sunlitfuxa-server · fuxa-serverEPSS 0.64%via NVD
CVE-2026-65822High· 7.6
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-67917Critical· 9.8
1mo ago

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content valida…

▾ MidnightEPSS 0.59%via NVD
CVE-2026-51346Critical· 9.1
1mo ago

SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.

SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.

▾ MidnightEPSS 0.70%via NVD
CVE-2026-50769Critical· 9.8
1mo ago

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=t…

▾ MidnightEPSS 0.60%via NVD
CVE-2026-64657High· 8.4
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path statem…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-16079Medium· 6.5
1mo ago

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, 1.6.12 due to insufficient escaping on the user supplied parameter and lack of…

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, 1.6.12 due to insufficient escaping on the user supplied parameter and lack of…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-15963Medium· 6.5
1mo ago

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the …

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option in all versions up to, and including, 11.2.1 due to insufficient escaping on the …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-15602Medium· 4.9
1mo ago

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.2.4 due to insufficient escaping on the user su…

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.2.4 due to insufficient escaping on the user su…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-19926High· 7.3
1mo ago

A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1

A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to s…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-19925Medium· 4.7
1mo ago

A vulnerability was detected in SourceCodester Stock Management System 1.0

A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=delete_supplier. The manipulation of the argument ID results in sql injection. The a…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-19923Medium· 6.3
1mo ago

A weakness has been identified in code-projects Online Shopping System 1.0

A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-19921Medium· 6.3
1mo ago

A vulnerability was identified in code-projects Online Shopping System 1.0

A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection. It is po…

▾ SunlitEPSS 0.33%via NVD
CWE-89 vulnerabilities (CVEs) — page 15 · VulnSea