VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

813 CVEsRSS

CVE-2026-53448High· 7.2
2mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without sanitization. The is_secu…

▾ Twilightcoturn_project · coturnEPSS 0.70%via NVD
CVE-2026-56690High· 8.5
2mo ago

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit th…

▾ Twilightdell · powerflex_managerEPSS 0.32%via NVD
CVE-2026-56689High· 7.7
2mo ago

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit th…

▾ Twilightdell · powerflex_managerEPSS 0.37%via NVD
CVE-2026-47199None
2mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT INTO OUTFILE queries, which could potentially work on self-hosted sites if database permissions are not well aligned a…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-15081None
2mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.

▾ SunlitEPSS 0.34%via NVD
CVE-2026-13242None
2mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.

▾ SunlitEPSS 0.28%via NVD
CVE-2026-57230Medium· 5.4
2mo ago

OpenReplay is a self-hosted session replay suite

OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy enabled built ClickHouse queries by inserting user input into the query string, including t…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-11321Medium· 6.4
2mo ago

The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, without parameterization or escaping, resulting in authenticated SQL injection

The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, without parameterization or escaping, resulting in authenticated SQL injection. An authent…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-61461High· 8.8
2mo ago

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escapin…

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escapin…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-5801Critical· 9.8
2mo ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. This issue affects …

▾ MidnightEPSS 0.58%via NVD
CVE-2026-56292High· 7.5PoC
2mo ago

A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered

A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.

▾ Midnightacymailing · acymailingEPSS 1.4%via NVD
GHSA-cgfv-jrfp-2r7vHigh
2mo ago

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export

▾ Twilightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-54760Critical
2mo ago

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

▾ Midnightlangroid · langroidEPSS 0.65%via GHSA
CVE-2026-14619Medium· 6.3
2mo ago

A flaw has been found in itsourcecode Hospital Management System 1.0

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /medicine.php. This manipulation of the argument editid causes sql injection. Remote exploitation of t…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-4321Critical· 9.8
2mo ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection. This issue affects Destekz: through 02062026. N…

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection. This issue affects Destekz: through 02062026. N…

▾ MidnightEPSS 0.47%via NVD
CVE-2026-4776High· 7.1
2mo ago

Mautic has SQL Injection in API Contact Filtering

Mautic has SQL Injection in API Contact Filtering

▾ Twilightmautic · mautic/coreEPSS 0.38%via GHSA
CVE-2026-50180High
2mo ago

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

▾ Twilightlangroid · langroidEPSS 0.69%via GHSA
CVE-2026-34105High· 8.8
2mo ago

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can pe…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-34104High· 8.8
2mo ago

Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'

Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated attacker can perform error-based SQL injec…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-34103High· 8.8
2mo ago

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where id = '\".$_GET['id'].\"'. An authenticated attacker can perform…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-34102High· 8.8
2mo ago

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. An authenticated attacker can perform error-based SQL injec…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-34101High· 8.8
2mo ago

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenti…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-34100High· 8.8
2mo ago

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private FROM files where id = '\".$_GET['id'].\"'. An authenticate…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-13542Medium· 6.3
3mo ago

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the argument doctorname leads to sql injection. It is possible…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13541Medium· 6.3
3mo ago

A weakness has been identified in itsourcecode Hospital Management System 1.0

A weakness has been identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /doctorchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The at…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13535Medium· 6.3
3mo ago

A flaw has been found in CodeAstro Human Resource Management System 1.0

A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulat…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13532Medium· 6.3
3mo ago

A weakness has been identified in itsourcecode Hospital Management System 1.0

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /departmentDoctor.php. This manipulation of the argument deptid causes sql injection. I…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13531Medium· 6.3
3mo ago

A security flaw has been discovered in itsourcecode Hospital Management System 1.0

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /department.php. The manipulation of the argument editid results in sql injection. The attack may be performe…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13530Medium· 6.3
3mo ago

A vulnerability was identified in itsourcecode Hospital Management System 1.0

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13529Medium· 5.6
3mo ago

A vulnerability was determined in YzmCMS up to 7.5

A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remot…

▾ SunlitEPSS 0.37%via NVD
CWE-89 vulnerabilities (CVEs) — page 20 · VulnSea