VulnSea

CWE-89

CVEs classified under CWE-89, newest first.

810 CVEsRSS

CVE-2026-18912High· 7.7
1w ago

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

▾ TwilightZohocorp · ManageEngine DataSecurity PlusEPSS 1.5%via NVD
CVE-2026-54647High· 7.2PoC
1w ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without…

▾ Midnightcubecart · v6EPSS 1.4%via NVD
CVE-2026-54646High· 7.2PoC
1w ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the ident…

▾ Midnightcubecart · v6EPSS 1.4%via NVD
CVE-2026-53557High· 7.7
1w ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/…

▾ Twilightdataease · SQLBotEPSS 0.34%via NVD
CVE-2026-53556Medium· 6.0PoC
1w ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_n…

▾ Twilightdataease · SQLBotEPSS 0.48%via NVD
CVE-2026-93426High· 8.5PoC
1w ago

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in fi…

▾ MidnightSigNoz · signozEPSS 0.50%via NVD
CVE-2026-54597High· 8.3PoC
1w ago

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform ti…

▾ Midnightitflow-org · itflowEPSS 0.43%via NVD
CVE-2026-54596High· 8.1PoC
1w ago

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the…

▾ Midnightitflow-org · itflowEPSS 0.48%via NVD
CVE-2026-54354High· 8.2
1w ago

MapServer is a system for developing web-based GIS applications

MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE …

▾ TwilightMapServer · MapServerEPSS 0.68%via NVD
CVE-2025-55787Critical· 9.8
1w ago

In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.

In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.

▾ MidnightEPSS 0.32%via NVD
CVE-2026-54524High· 7.1
1w ago

Frappe HR is an open-source human resources management solution (HRMS)

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/repo…

▾ Twilightfrappe · hrmsEPSS 0.48%via NVD
CVE-2026-52851High· 7.1PoC
1w ago

Traccar is an open source GPS tracking system

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permi…

▾ Midnighttraccar · traccarEPSS 0.39%via NVD
CVE-2026-92926High· 7.3PoC
1w ago

A vulnerability has been found in code-projects Matrimonial System 1.0

A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. Th…

▾ Midnightcode-projects · Matrimonial SystemEPSS 0.43%via NVD
CVE-2026-93292High· 8.5PoC
1w ago

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attac…

▾ MidnightSigNoz · signozEPSS 0.40%via NVD
CVE-2026-79752Critical· 9.2PoC
1w ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBui…

▾ Abyssalcakephp · cakephpEPSS 0.62%via NVD
CVE-2026-66631High· 7.6
1w ago

Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

▾ TwilightMoreconvert Team · smart-wishlist-for-more-convertEPSS 0.38%via NVD
CVE-2026-66630High· 7.6
1w ago

Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

▾ TwilightPublishPress · organize-seriesEPSS 0.38%via NVD
CVE-2026-66628High· 7.6
1w ago

Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.

Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.

▾ TwilightWP Lab · wp-lister-for-ebayEPSS 0.38%via NVD
CVE-2026-66626High· 7.6
1w ago

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

▾ TwilightSonal S Sinha · skt-addons-for-elementorEPSS 0.38%via NVD
CVE-2026-66625High· 7.6
1w ago

Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

▾ TwilightWCVendors · wc-vendorsEPSS 0.38%via NVD
CVE-2026-66624High· 7.6
1w ago

Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

▾ TwilightLudwig You · wpmastertoolkitEPSS 0.38%via NVD
CVE-2026-66619High· 7.6
1w ago

Administrator SQL Injection in Newsletters <= 4.18 versions.

Administrator SQL Injection in Newsletters <= 4.18 versions.

▾ TwilightTribulant Software · newsletters-liteEPSS 0.38%via NVD
CVE-2026-66618High· 7.6
1w ago

Administrator SQL Injection in WP Maps <= 4.9.9 versions.

Administrator SQL Injection in WP Maps <= 4.9.9 versions.

▾ TwilightFlipper Code · wp-google-map-pluginEPSS 0.38%via NVD
CVE-2026-66580High· 8.5
1w ago

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

▾ TwilightRexTheme · best-woocommerce-feedEPSS 0.36%via NVD
CVE-2026-92903High· 8.2
1w ago

Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries

Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a maliciou…

▾ TwilightSnowflake · snowflake-cliEPSS 0.19%via NVD
CVE-2026-87963High· 8.6
1w ago

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attacker…

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attacker…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-75513Critical· 9.1PoC
1w ago

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQ…

▾ AbyssalJasperFx · martenEPSS 0.47%via NVD
CVE-2026-92526Medium· 6.3PoC
1w ago

A flaw has been found in itsourcecode Leave Management System 1.0

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched re…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-86865High· 7.2
1w ago

Tanium addressed a SQL injection vulnerability in Asset.

Tanium addressed a SQL injection vulnerability in Asset.

▾ TwilightTanium · AssetEPSS 0.45%via NVD
CVE-2026-87024High· 7.2
1w ago

Tanium addressed a SQL injection vulnerability in Asset.

Tanium addressed a SQL injection vulnerability in Asset.

▾ TwilightTanium · AssetEPSS 0.45%via NVD
CWE-89 vulnerabilities (CVEs) — page 6 · VulnSea