VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

813 CVEsRSS

CVE-2026-13527High· 7.3
3mo ago

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /preview4.php. Such manipulation of the argument course_year_section leads to sql injection. …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-13526High· 7.3
3mo ago

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_class.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-13525Medium· 6.3
3mo ago

A vulnerability was detected in CodeAstro Human Resource Management System 1.0

A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulatio…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13521High· 7.3
3mo ago

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such manipulation of the argument course_year_section lea…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-13520Medium· 6.3
3mo ago

A vulnerability was determined in itsourcecode Hospital Management System 1.0

A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-49048NonePoC
3mo ago

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

▾ TwilightEPSS 0.56%via NVD
CVE-2026-54350Critical· 10.0PoC
3mo ago

Budibase has nonymous NoSQL operator injection via published-app query templates

Budibase has nonymous NoSQL operator injection via published-app query templates

▾ Abyssalbudibase · @budibase/serverEPSS 0.54%via GHSA
CVE-2025-66336High· 8.1
3mo ago

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

▾ Twilightdoris-mcp-server · doris-mcp-serverEPSS 0.56%via OSV
CVE-2026-12789Medium· 4.7
3mo ago

A vulnerability was identified in ILIAS Learning Management System 11.0

A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::executeQueries of the file components/ILIAS/Tracking/classes/class.ilTrQuery.php of the component Learning Progress Track…

▾ SunlitEPSS 0.33%via NVD
CVE-2019-25761High· 7.1
3mo ago

Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter

Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter. Attackers can send GET requests to in…

▾ Twilightjoomboost · joomcrmEPSS 0.40%via NVD
CVE-2019-25757High· 7.1
3mo ago

Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters

Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can send POST request…

▾ Twilightwdmtech · vwishlistEPSS 0.40%via NVD
CVE-2019-25756High· 8.2
3mo ago

Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter

Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the…

▾ Twilightwdmtech · vaccountEPSS 0.49%via NVD
CVE-2019-25755High· 8.2
3mo ago

Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter

Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to th…

▾ Twilightwdmtech · vreviewEPSS 0.49%via NVD
CVE-2019-25754High· 8.2
3mo ago

Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter

Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST reques…

▾ Twilightwdmtech · vrestaurantEPSS 0.49%via NVD
CVE-2017-20275High· 8.2
3mo ago

Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter

Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to in…

▾ Twilighthenryschorradt · bridgeEPSS 0.43%via NVD
CVE-2017-20273High· 8.2
3mo ago

Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter

Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requ…

▾ Twilightjoomalshowroom · event_registration_pro_calendarEPSS 0.43%via NVD
CVE-2017-20271High· 8.2
3mo ago

Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter

Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to ind…

▾ Twilightnordmograph · streetguessr_gameEPSS 0.43%via NVD
CVE-2017-20270High· 8.2
3mo ago

Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters

Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET req…

▾ Twilightraindropsinfotech · twitch_tvEPSS 0.49%via NVD
CVE-2017-20269High· 8.2
3mo ago

Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path

Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint …

▾ Twilightterrywcarter · kissgalleryEPSS 0.49%via NVD
CVE-2017-20268High· 8.2
3mo ago

Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter

Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requ…

▾ Twilightzcontent · zap_calendar_liteEPSS 0.49%via NVD
CVE-2026-12050Medium· 4.3
3mo ago

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid})

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a boun…

▾ Sunlitpgadmin · pgadmin_4EPSS 0.43%via NVD
GHSA-9ggv-8w38-r7pmMedium· 5.9
3mo ago

TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)

TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)

▾ Sunlittypeorm · typeormvia GHSA
CVE-2026-54419Critical· 9.8
3mo ago

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. The application has no authe…

▾ MidnightEPSS 0.64%via NVD
CVE-2026-55740Critical· 9.8
3mo ago

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is concatenated dire…

▾ MidnightEPSS 0.50%via NVD
GHSA-qqf5-x7mj-v43pHigh· 8.4
3mo ago

budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL

budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL

▾ Twilightbudibase · budibasevia GHSA
CVE-2026-55405High· 7.6
3mo ago

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

▾ Twilightlangchain4j · dev.langchain4j:langchain4j-mariadbEPSS 0.47%via GHSA
CVE-2026-54310Medium· 9.9
3mo ago

n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes

n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes

▾ Sunlitn8n · n8nEPSS 0.55%via GHSA
CVE-2026-54313Medium· 7.7
3mo ago

n8n: NoSQL Injection in MongoDB Node Find And Replace Operation

n8n: NoSQL Injection in MongoDB Node Find And Replace Operation

▾ Sunlitn8n · n8nEPSS 0.34%via GHSA
CVE-2026-6428High· 7.6
3mo ago

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated…

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-49741High
3mo ago

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.37%via GHSA
CWE-89 vulnerabilities (CVEs) — page 21 · VulnSea