VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

812 CVEsRSS

CVE-2026-19920Medium· 6.3
1mo ago

A vulnerability was determined in code-projects Online Shopping System 1.0

A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remo…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-19919High· 7.3
1mo ago

A vulnerability was found in code-projects Online Shopping System 1.0

A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be per…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-19917Medium· 6.3
1mo ago

A flaw has been found in code-projects Online Food Order System 1.0

A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox can lead to sql injection. The attack …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-19905High· 7.3
1mo ago

A weakness has been identified in Jinher OA 1.0

A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to init…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-19899High· 7.3
1mo ago

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-16007None
1mo ago

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.

▾ SunlitEPSS 0.34%via NVD
CVE-2026-48528Critical· 9.8
1mo ago

Metacat is data repository software that helps researchers preserve, share, and discover data

Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST AP…

▾ MidnightEPSS 0.47%via NVD
CVE-2026-73850None
1mo ago

Emlog is an open source website building system

Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php.

▾ SunlitEPSS 0.37%via NVD
CVE-2026-73663None
1mo ago

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without e…

▾ SunlitEPSS 1.7%via NVD
CVE-2019-25765High· 7.5
1mo ago

ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script

ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers…

▾ TwilightEPSS 0.74%via NVD
CVE-2026-73670High· 7.2
1mo ago

A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET o…

A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET o…

▾ TwilightEPSS 0.53%via NVD
CVE-2024-58374High· 7.5
1mo ago

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request U…

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request U…

▾ TwilightEPSS 0.74%via NVD
CVE-2026-73408High· 7.6
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table …

▾ TwilightEPSS 0.45%via NVD
CVE-2026-15741High· 8.8
1mo ago

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf…

▾ Twilightpostgresql · postgresqlEPSS 0.47%via NVD
CVE-2026-44741High· 8.8
1mo ago

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON i…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-73300Critical· 9.6
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject…

▾ MidnightEPSS 0.56%via NVD
CVE-2026-73331High· 7.1
1mo ago

CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing SQL syntax that the database backend evaluates…

CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing SQL syntax that the database backend evaluates…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-73211Critical· 9.8
1mo ago

PeerTube is an ActivityPub-federated video streaming platform

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to…

▾ MidnightEPSS 0.73%via NVD
CVE-2026-73069Critical· 9.1
1mo ago

Twenty is an open-source CRM (customer relationship management) platform

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVecto…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-46670Critical· 9.8PoC
1mo ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrar…

▾ AbyssalEPSS 2.0%via NVD
CVE-2022-50997High· 7.5
1mo ago

Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id…

Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id…

▾ TwilightEPSS 0.62%via NVD
CVE-2016-20097High· 7.5
1mo ago

Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, …

Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, …

▾ TwilightEPSS 0.63%via NVD
CVE-2026-65673High· 7.8
1mo ago

Microsoft Entra Connect Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Microsoft Entra ConnectEPSS 0.32%via CVEORG
CVE-2026-63106Critical· 9.8
1mo ago

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameteriza…

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameteriza…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-72908Medium· 6.5
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced pos…

▾ SunlitEPSS 0.51%via NVD
CVE-2026-72731High· 7.1
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-staff members of a group a query is sh…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-72565Critical· 9.8
1mo ago

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.

▾ MidnightEPSS 0.68%via NVD
CVE-2026-19384High· 7.3
1mo ago

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injec…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-19364Medium· 6.3
1mo ago

A vulnerability was determined in itsourcecode Hospital Management System 1.0

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argument delid causes sql injection. The at…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-19355High· 7.3
1mo ago

A vulnerability was determined in MingSoft MCMS up to 3.0.6

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can l…

▾ TwilightEPSS 0.41%via NVD
CWE-89 vulnerabilities (CVEs) — page 16 · VulnSea