VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

813 CVEsRSS

CVE-2026-13754Medium· 6.5
2mo ago

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user supplied parameter and la…

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user supplied parameter and la…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-12753High· 7.5
2mo ago

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the…

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-50030None
2mo ago

DataEase is an open source data visualization and analysis tool

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/datasetData/previewSql, accepts PreviewSqlDTO.sql, PreviewSqlDTO.da…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-45320None
2mo ago

DataEase is an open source data visualization and analysis tool

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transFilter(), whose final branch returns raw user input for non-in and…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-47142High
2mo ago

MantisBT: SQL Injection via history_order Configuration Value

MantisBT: SQL Injection via history_order Configuration Value

▾ Twilightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-47295High· 8.8
2mo ago

Microsoft SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SQL Server 2016 Service Pack 3 (GDR)EPSS 0.99%via CVEORG
CVE-2026-47296High· 7.8
2mo ago

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · sql_server_2016EPSS 0.69%via NVD
CVE-2026-45262Critical· 9.9
2mo ago

FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`

FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
GHSA-7xw9-549r-8jrcHigh· 8.5
2mo ago

DIRAC: SQL injection and lack of access control in PilotManager service

DIRAC: SQL injection and lack of access control in PilotManager service

▾ TwilightDIRAC · DIRACvia GHSA
CVE-2026-15537High· 7.3
2mo ago

A security flaw has been discovered in SourceCodester Online Book Store System 1.0

A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection. The attack can b…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-15536Medium· 6.3
2mo ago

A vulnerability was identified in itsourcecode Hospital Management System 1.0

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid leads to sql injection. Remote exploitation of the a…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-15523Medium· 6.3
2mo ago

A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0

A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-15517High· 7.3
2mo ago

A flaw has been found in Jinher OA 1.0

A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx. This manipulation of the argument httpOID causes sql injection. Remote exploitation of the att…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-15514High· 7.3
2mo ago

A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06

A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCService.query of the file /customizemt/xkq/rpc.jsp of the component PHPRPC Remote Call Interface. Executing a manipula…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-15502Medium· 6.3PoC
2mo ago

A vulnerability was detected in AojiaoZero Antaris 1.0

A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. Th…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-56281Low· 3.8PoC
2mo ago

Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL…

Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL…

▾ TwilightCapgo · CapgoEPSS 0.33%via NVD
CVE-2026-15498High· 7.3
2mo ago

A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c

A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impacts an unknown function of the file users.php of the component Login. Such manipulation of the argument Login leads to …

▾ TwilightEPSS 0.41%via NVD
CVE-2026-15494Medium· 4.7
2mo ago

A flaw has been found in AMTT Hotel Broadband Operation System 1.0

A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/network/switch_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to l…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-15490High· 7.3
2mo ago

A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99

A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this issue is some unknown functionality of the file proses/add.php. The manipulation of the argument kode_produk…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-15489High· 7.3
2mo ago

A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99

A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability is an unknown functionality of the file proses/login.php. The manipulation of the argument Username…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-15482High· 7.3
2mo ago

A weakness has been identified in Aster Telecom Azcall 10/11

A weakness has been identified in Aster Telecom Azcall 10/11. This issue affects some unknown processing of the file /azcall/adm/gestao_loja/sis.php?t=consultar of the component HTTP Handler. Executing a manipulation of the argument nome…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-15478Medium· 6.3
2mo ago

A flaw has been found in IceHRM up to 35.0.1

A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employee…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-15477Medium· 6.3
2mo ago

A vulnerability was detected in Bahmni bahmnicore up to 0.93

A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test resu…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-60090Critical· 9.8
2mo ago

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the …

▾ MidnightEPSS 0.70%via NVD
CVE-2026-4661High· 7.5
2mo ago

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in all versions up to, and including, 2.2.2

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in all versions up to, and including, 2.2.2. This is due to insufficient esc…

▾ TwilightEPSS 0.51%via NVD
CVE-2025-5017Medium· 4.9
2mo ago

The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter an…

The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter an…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-15335High· 7.5
2mo ago

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of suf…

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of suf…

▾ TwilightEPSS 0.76%via NVD
CVE-2026-15073Medium· 6.5
2mo ago

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied…

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-15072Medium· 6.5
2mo ago

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied…

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-13262Medium· 6.5
2mo ago

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on t…

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on t…

▾ SunlitEPSS 0.59%via NVD
CWE-89 vulnerabilities (CVEs) — page 19 · VulnSea