VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

813 CVEsRSS

CVE-2025-10595Medium· 6.3
1y ago

A vulnerability has been found in SourceCodester Online Student File Management System 1.0

A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/delete_user.php. The manipulation of the argument user_id leads to sql in…

▾ Sunlitjanobe · online_student_file_management_systemEPSS 0.44%via NVD
CVE-2025-10594Medium· 6.3
1y ago

A flaw has been found in SourceCodester Online Student File Management System 1.0

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_student.php. Executing manipulation of the argument stud_id can lead …

▾ Sunlitjanobe · online_student_file_management_systemEPSS 0.34%via NVD
CVE-2025-10593Medium· 6.3
1y ago

A vulnerability was detected in SourceCodester Online Student File Management System 1.0

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It…

▾ Sunlitjanobe · online_student_file_management_systemEPSS 0.31%via NVD
CVE-2025-10592Medium· 6.3
1y ago

A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0

A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search…

▾ Sunlititsourcecode · online_public_access_catalogEPSS 0.38%via NVD
CVE-2025-57631Critical· 9.8
1y ago

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

▾ Midnighttduckcloud · tduckEPSS 0.82%via NVD
CVE-2025-9807High· 7.5
1y ago

The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient …

The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient …

▾ TwilightEPSS 0.35%via NVD
CVE-2025-10210Medium· 6.3PoC
1y ago

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launc…

▾ Twilightchancms · chancmsEPSS 1.3%via NVD
CVE-2025-9943Critical· 9.1
1y ago

An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service

An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attac…

▾ MidnightEPSS 0.40%via NVD
CVE-2025-58375High· 8.1
1y ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive informatio…

▾ TwilightEPSS 0.34%via NVD
CVE-2025-10012Medium· 6.3PoC
1y ago

A security vulnerability has been detected in Portabilis i-Educar up to 2.10

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injectio…

▾ Twilightportabilis · i-educarEPSS 0.38%via NVD
CVE-2025-9770High· 7.3
1y ago

A weakness has been identified in Campcodes Hospital Management System 1.0

A weakness has been identified in Campcodes Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Dashboard Login. This manipulation of the argument Password…

▾ Twilightcampcodes · hospital_management_systemEPSS 0.47%via NVD
CVE-2025-9767High· 7.3
1y ago

A vulnerability was determined in itsourcecode Sports Management System 1.0

A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /Admin/sporttype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be exec…

▾ Twilightangeljudesuarez · sports_management_systemEPSS 0.53%via NVD
CVE-2025-9766High· 7.3
1y ago

A vulnerability was found in itsourcecode Sports Management System 1.0

A vulnerability was found in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/facilitator.php. Performing manipulation of the argument code results in sql injection. Remote exploit…

▾ Twilightangeljudesuarez · sports_management_systemEPSS 0.60%via NVD
CVE-2025-9765High· 7.3
1y ago

A vulnerability has been found in itsourcecode Sports Management System 1.0

A vulnerability has been found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/tournament_details.php. Such manipulation of the argument ID leads to sql injection. The attack m…

▾ Twilightangeljudesuarez · sports_management_systemEPSS 0.42%via NVD
CVE-2025-9606Medium· 6.3PoC
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql…

▾ Twilightportabilis · i-educarEPSS 0.34%via NVD
CVE-2025-9594High· 7.3
1y ago

A vulnerability has been found in itsourcecode Apartment Management System 1.0

A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /report/complain_info.php. The manipulation of the argument vid leads to sql injection. The attack is…

▾ Twilightadmerc · apartment_management_systemEPSS 0.42%via NVD
CVE-2025-9593High· 7.3
1y ago

A flaw has been found in itsourcecode Apartment Management System 1.0

A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/unit_status_info.php. Executing manipulation of the argument usid can lead to sql injection. The attack can be exe…

▾ Twilightadmerc · apartment_management_systemEPSS 0.44%via NVD
CVE-2025-9592High· 7.3
1y ago

A vulnerability was detected in itsourcecode Apartment Management System 1.0

A vulnerability was detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/bill_info.php. Performing manipulation of the argument vid results in sql injection. Remote expl…

▾ Twilightadmerc · apartment_management_systemEPSS 0.51%via NVD
CVE-2025-57819Critical· 9.8CISA KEV0dayPoC
1y ago

FreePBX is an open-source web-based graphical user interface

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrar…

▾ Hadalsangoma · freepbxEPSS 85%via NVD
CVE-2025-51972Medium· 6.5
1y ago

A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.

A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.

▾ Sunlitpuneethreddyhc · online_shopping_system_advancedEPSS 0.24%via NVD
CVE-2025-51971Medium· 5.4
1y ago

A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0

A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML enc…

▾ Sunlitpuneethreddyhc · online_shopping_system_advancedEPSS 0.27%via NVD
CVE-2025-51969Medium· 6.5
1y ago

A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0

A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL stat…

▾ Sunlitpuneethreddyhc · online_shopping_system_advancedEPSS 0.24%via NVD
CVE-2025-51968Medium· 6.5
1y ago

A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0

A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject a…

▾ Sunlitpuneethreddyhc · online_shopping_system_advancedEPSS 0.24%via NVD
CVE-2025-54720Critical· 9.3
1y ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons nest-addons allows SQL Injection.This issue affects Nest Addons: from n/a through <= 1.6.3.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons nest-addons allows SQL Injection.This issue affects Nest Addons: from n/a through <= 1.6.3.

▾ MidnightEPSS 0.29%via NVD
CVE-2025-34162None
1y ago

An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface

An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface. …

▾ SunlitEPSS 0.63%via NVD
CVE-2025-9531Medium· 6.3PoC
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Module. Performing a manipulation of the argument cod_agenda results in sql injecti…

▾ Twilightportabilis · i-educarEPSS 0.40%via NVD
CVE-2025-9236Medium· 6.3PoC
1y ago

A vulnerability has been found in Portabilis i-Educar up to 2.10

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descri…

▾ Twilightportabilis · i-educarEPSS 0.39%via NVD
CVE-2025-54790Medium· 6.5
1y ago

Files is a module for managing files inside spaces and user profiles

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries without direct output, potentially allowing unauthorized dat…

▾ Sunlithumhub · filesEPSS 0.31%via NVD
CVE-2025-20272Medium· 4.3
1y ago

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This v…

A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This v…

▾ Sunlitcisco · prime_infrastructureEPSS 0.32%via NVD
CVE-2025-26241Medium· 6.5
1y ago

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

▾ Sunlitenhancesoft · osticketEPSS 0.29%via NVD
CWE-89 vulnerabilities (CVEs) — page 25 · VulnSea