Vulnerabilities (CVE)

Filtered by CWE-89
Total 19979 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-50567 2026-07-05 N/A 10.0 CRITICAL
Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-controlled SQL statements, potentially leading to arbitrary PHP code execution.
CVE-2025-29267 2026-07-05 N/A 6.5 MEDIUM
SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to obtain a sensitive information via the cid parameter in the GET request.
CVE-2024-38889 1 Horizoncloud 1 Caterease 2026-07-05 N/A 9.8 CRITICAL
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.
CVE-2024-35584 1 Os4ed 1 Opensis 2026-07-05 N/A 8.8 HIGH
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
CVE-2024-34334 1 Ordat 1 Ordat.erp 2026-07-05 N/A 7.5 HIGH
ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.
CVE-2024-48733 2026-07-05 N/A 8.8 HIGH
SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the POST body request. NOTE: this is disputed by the vendor because SQL statement execution is allowed for authorized users.
CVE-2026-52673 2026-07-05 N/A 6.5 MEDIUM
SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component
CVE-2025-70397 1 Jizhicms 1 Jizhicms 2026-07-05 N/A 7.2 HIGH
jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.
CVE-2025-60641 2026-07-05 N/A 6.5 MEDIUM
The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexcel'])), where $_POST['mexcel'] is user-controlled input. This input is decoded from base64 and deserialized without validation or use of the allowed_classes option, allowing an attacker to inject arbitrary PHP objects. This can lead to malicious behavior, such as Remote Code Execution (RCE), SQL Injection, Path Traversal, or Denial of Service, depending on the availability of exploitable classes in the Vfront codebase or its dependencies.
CVE-2025-60307 1 Carmelo 1 Computer Laboratory System 2026-07-05 N/A 9.8 CRITICAL
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.
CVE-2025-56421 1 Limesurvey 1 Limesurvey 2026-07-05 N/A 7.5 HIGH
SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.
CVE-2025-56401 1 Ziragroup 1 Wbrm 2026-07-05 N/A 7.6 HIGH
ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
CVE-2025-55849 1 Weiphp 1 Weiphp 2026-07-05 N/A 8.4 HIGH
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
CVE-2025-52025 1 Aptsys 1 Gemscms Backend 2026-07-05 N/A 9.4 CRITICAL
An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or parameterization. This allows an attacker to inject and execute arbitrary SQL code by submitting crafted input in the id parameter, leading to unauthorized data access or modification.
CVE-2025-51683 1 Mjobtime 1 Mjobtime 2026-07-05 N/A 9.8 CRITICAL
A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .
CVE-2025-50383 1 Easyappointments 1 Easy\!appointments 2026-07-05 N/A 8.1 HIGH
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
CVE-2023-49440 2026-07-05 N/A 8.8 HIGH
AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."
CVE-2025-52327 1 Carmelogarcia 1 Restaurant Order System 2026-07-05 N/A 7.8 HIGH
SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file
CVE-2025-51660 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
CVE-2025-51659 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.