VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

813 CVEsRSS

CVE-2026-63221Critical· 9.4
1mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled conditio…

▾ Midnightcodeigniter4 · codeigniter4/frameworkEPSS 0.61%via NVD
CVE-2026-58048NonePoC
1mo ago

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

▾ TwilightEPSS 0.56%via NVD
CVE-2026-17351Critical· 9.0PoC
1mo ago

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TR…

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TR…

▾ AbyssalEPSS 0.48%via NVD
CVE-2026-17346High· 8.8
1mo ago

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on …

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on …

▾ TwilightEPSS 0.61%via NVD
CVE-2026-52887Critical· 10.0PoC
1mo ago

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

▾ Abyssalnocobase · @nocobase/plugin-notification-in-app-messageEPSS 0.89%via GHSA
CVE-2026-45376Medium· 5.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity ex…

▾ Sunlitdecidim-admin · decidim-adminEPSS 0.60%via NVD
CVE-2026-62845Medium· 4.7
1mo ago

Kamaji is the Hosted Control Plane Manager for Kubernetes

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via f…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-11973Medium· 4.9
2mo ago

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of suffi…

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of suffi…

▾ SunlitEPSS 0.51%via NVD
CVE-2026-6881None
2mo ago

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This is…

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This is…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-54658Critical· 9.8
2mo ago

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

▾ Midnighthypequery · @hypequery/clickhouseEPSS 0.82%via GHSA
CVE-2026-65876None
2mo ago

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

▾ SunlitEPSS 0.39%via NVD
GHSA-pmpg-2mxq-6xwrHigh· 7.1
2mo ago

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-q6x4-v3qx-85qwCritical· 9.6
2mo ago

Budibase: SQL Injection via `multipleStatements: true`

Budibase: SQL Injection via `multipleStatements: true`

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-2xgg-r2wc-c5r2High· 7.6
2mo ago

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

▾ Twilightbudibase · @budibase/servervia GHSA
CVE-2026-24552High· 8.5
2mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create mediavine-create allows Blind SQL Injection.This issue affects Create: from n/a through 2.5.3.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create mediavine-create allows Blind SQL Injection.This issue affects Create: from n/a through 2.5.3.

▾ TwilightJohn-Michael L'Allier · mediavine-createEPSS 0.36%via NVD
CVE-2026-65526High· 8.5
2mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

▾ TwilightEPSS 0.36%via NVD
GHSA-jqwr-vx3p-r266Medium
2mo ago

n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

▾ Sunlitn8n · n8nvia GHSA
GHSA-652q-gvq3-74qvMedium
2mo ago

n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-59257Medium
2mo ago

n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

▾ Sunlitn8n · n8nEPSS 0.57%via GHSA
CVE-2016-20096Critical· 9.8PoC
2mo ago

Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login e…

▾ AbyssalKunshi Network Technology Co., Ltd. · Linknat VOS3000EPSS 0.67%via CVEORG
CVE-2026-15829High· 8.1
2mo ago

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, times…

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, times…

▾ Twilightgoogle · mcp_toolbox_for_databasesEPSS 0.18%via NVD
CVE-2026-16228High· 7.3
2mo ago

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible t…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-16227High· 7.3
2mo ago

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack m…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-16154High· 7.3
2mo ago

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-16152High· 7.3
2mo ago

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-16131Medium· 6.3
2mo ago

A weakness has been identified in itsourcecode Hospital Management System 1.0

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-9586Critical· 9.8CISA KEVPoC
2mo ago

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …

▾ Hadalsangoma · switchvoxEPSS 19%via NVD
CVE-2026-60137Medium· 5.9CISA KEVPoC
2mo ago

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

▾ MidnightEPSS 5.9%via NVD
CVE-2026-44739High· 8.7
2mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL con…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-15022Medium· 6.5
2mo ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied p…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied p…

▾ SunlitEPSS 0.57%via NVD
CWE-89 vulnerabilities (CVEs) — page 18 · VulnSea