VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

813 CVEsRSS

CVE-2025-46252High· 7.6
1y ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a thr…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a thr…

▾ Twilightkofimokome · message_filter_for_contact_form_7EPSS 0.39%via NVD
CVE-2025-26988Critical· 9.3
1y ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a thr…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a thr…

▾ Midnightcozyvision · sms_alert_order_notificationsEPSS 0.52%via NVD
CVE-2024-53597Medium· 6.3
1y ago

masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.

masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.

▾ SunlitEPSS 0.31%via NVD
CVE-2023-7299Medium· 6.3
1y ago

A vulnerability was found in DataGear up to 4.60

A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the argument sql leads to sql injection. The attack can be i…

▾ Sunlitdatagear · datagearEPSS 0.64%via NVD
CVE-2024-7837High· 8.2
1y ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: before 15.0.1.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: before 15.0.1.

▾ TwilightEPSS 0.50%via NVD
CVE-2024-44004Critical· 9.3
2y ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection. This issue affects WPCargo Track & Trace: before 8.0.4.

▾ Midnightwptaskforce · track_&_traceEPSS 0.46%via NVD
CVE-2024-27304High· 8.1PoC
2y ago

pgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…

▾ MidnightRed Hat · RHACS 4.3 for RHEL 8EPSS 1.1%via CSAF
CVE-2023-33677High· 7.5
2y ago

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

▾ Twilightoretnom23 · lost_and_found_information_systemEPSS 0.41%via NVD
CVE-2023-4548Medium· 6.3PoC
3y ago

A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3

A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql inje…

▾ Twilightspa-cart · ecommerce_cmsEPSS 32%via NVD
CVE-2023-39807Critical· 9.8
3y ago

N.V.K.INTER CO., LTD

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.

▾ Midnightnvki · intelligent_broadband_subscriber_gatewayEPSS 0.62%via NVD
CVE-2023-3617High· 7.3
3y ago

A vulnerability was found in SourceCodester Best POS Management System 1.0

A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation of the argument userna…

▾ Twilightmayurik · best_pos_management_systemEPSS 0.82%via NVD
CVE-2023-2208Medium· 6.3
3y ago

A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability, which was classified as critical, has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file details.php. The manipulation of the argument id leads to sql …

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.61%via NVD
CVE-2023-2207Medium· 6.3
3y ago

A vulnerability classified as critical was found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability classified as critical was found in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file contactus1.php. The manipulation of the argument email leads to sql injection. The…

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.61%via NVD
CVE-2023-2206Medium· 6.3
3y ago

A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability classified as critical has been found in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file contactus.php. The manipulation of the argument email leads to sql injection. It is poss…

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.74%via NVD
CVE-2023-2205Medium· 6.3
3y ago

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /function/login.php. The manipulation of the argument email l…

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.61%via NVD
CVE-2023-2204Medium· 6.3
3y ago

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file faqs.php. The manipulation of the argument id leads …

▾ Sunlitcampcodes · retro_basketball_shoes_online_storeEPSS 0.61%via NVD
CVE-2023-27205Critical· 9.8
3y ago

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.

▾ Midnightmayurik · best_pos_management_systemEPSS 0.79%via NVD
CVE-2023-27204Critical· 9.8
3y ago

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.

▾ Midnightmayurik · best_pos_management_systemEPSS 0.79%via NVD
CVE-2023-27203Critical· 9.8
3y ago

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.

▾ Midnightmayurik · best_pos_management_systemEPSS 0.79%via NVD
CVE-2023-27202Critical· 9.8
3y ago

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.

▾ Midnightmayurik · best_pos_management_systemEPSS 0.79%via NVD
CVE-2023-0946Medium· 6.3
3y ago

A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical

A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The manipulation of the argument i…

▾ Sunlitmayurik · best_pos_management_systemEPSS 0.49%via NVD
CVE-2022-35156Critical· 9.8
3y ago

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

▾ Midnightphpgurukul · bus_pass_management_systemEPSS 1.2%via NVD
CVE-2022-38615High· 8.8
4y ago

SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.

SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.

▾ Twilightbpcbt · smartvista_front-endEPSS 0.92%via NVD
CVE-2022-29709High· 7.5
4y ago

CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

▾ Twilightcommunilink · clink_officeEPSS 1.3%via NVD
CVE-2022-31384Critical· 9.8
4y ago

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.

▾ Midnightphpgurukul · directory_management_systemEPSS 1.7%via NVD
CVE-2022-31383Critical· 9.8
4y ago

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

▾ Midnightphpgurukul · directory_management_systemEPSS 1.7%via NVD
CVE-2022-31382Critical· 9.8
4y ago

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

▾ Midnightphpgurukul · directory_management_systemEPSS 1.7%via NVD
CVE-2021-41672Medium· 6.5
4y ago

PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php

PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retri…

▾ Sunlitpeel · peel_shoppingEPSS 1.4%via NVD
CVE-2022-31340Critical· 9.8
4y ago

Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.

Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.

▾ Midnightargie · simple_inventory_systemEPSS 1.1%via NVD
CVE-2022-31339High· 7.2
4y ago

Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.

Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.

▾ Twilightargie · simple_inventory_systemEPSS 1.0%via NVD
CWE-89 vulnerabilities (CVEs) — page 26 · VulnSea