CWE-89
CVEs classified under CWE-89, newest first.
810 CVEsRSS
CVE-2026-18912High· 7.7ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
CVE-2026-54647High· 7.2PoCCubeCart is an ecommerce software solution
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without…
CVE-2026-54646High· 7.2PoCCubeCart is an ecommerce software solution
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the ident…
CVE-2026-53557High· 7.7SQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/…
CVE-2026-53556Medium· 6.0PoCSQLBot is an intelligent Text-to-SQL system based on large language models and RAG
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_n…
CVE-2026-93426High· 8.5PoCSigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in fi…
CVE-2026-54597High· 8.3PoCITFlow provides an IT documentation, ticketing and accounting system for small managed service providers
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform ti…
CVE-2026-54596High· 8.1PoCITFlow provides an IT documentation, ticketing and accounting system for small managed service providers
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the…
CVE-2026-54354High· 8.2MapServer is a system for developing web-based GIS applications
MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE …
CVE-2025-55787Critical· 9.8In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
CVE-2026-54524High· 7.1Frappe HR is an open-source human resources management solution (HRMS)
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/repo…
CVE-2026-52851High· 7.1PoCTraccar is an open source GPS tracking system
Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permi…
CVE-2026-92926High· 7.3PoCA vulnerability has been found in code-projects Matrimonial System 1.0
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. Th…
CVE-2026-93292High· 8.5PoCSigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attac…
CVE-2026-79752Critical· 9.2PoCCakePHP is a rapid development framework for PHP
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBui…
CVE-2026-66631High· 7.6Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
CVE-2026-66630High· 7.6Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
CVE-2026-66628High· 7.6Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
CVE-2026-66626High· 7.6Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
CVE-2026-66625High· 7.6Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
CVE-2026-66624High· 7.6Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
CVE-2026-66619High· 7.6Administrator SQL Injection in Newsletters <= 4.18 versions.
Administrator SQL Injection in Newsletters <= 4.18 versions.
CVE-2026-66618High· 7.6Administrator SQL Injection in WP Maps <= 4.9.9 versions.
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-66580High· 8.5Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
CVE-2026-92903High· 8.2Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries
Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a maliciou…
CVE-2026-87963High· 8.6The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attacker…
The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attacker…
CVE-2026-75513Critical· 9.1PoCMarten is a .NET Transactional Document DB and Event Store on PostgreSQL
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQ…
CVE-2026-92526Medium· 6.3PoCA flaw has been found in itsourcecode Leave Management System 1.0
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched re…
CVE-2026-86865High· 7.2Tanium addressed a SQL injection vulnerability in Asset.
Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-87024High· 7.2Tanium addressed a SQL injection vulnerability in Asset.
Tanium addressed a SQL injection vulnerability in Asset.