Vulnerabilities (CVE)

Filtered by CWE-89
Total 19979 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-51658 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
CVE-2025-51657 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
CVE-2025-51656 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
CVE-2025-51655 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
CVE-2025-51654 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
CVE-2025-51653 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
CVE-2025-51652 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.
CVE-2025-50585 1 Daycloud 1 Studentmanage 2026-07-05 N/A 8.8 HIGH
StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.
CVE-2025-50341 2026-07-05 N/A 9.8 CRITICAL
A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.
CVE-2025-44608 1 Vishalmathur 1 Cloudclassroom-php Project 2026-07-05 N/A 6.5 MEDIUM
CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.
CVE-2024-55160 1 G-fast 1 Gfast 2026-07-05 N/A 9.8 CRITICAL
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.
CVE-2024-53480 1 Phpgurukul 1 Beauty Parlour Management System 2026-07-05 N/A 9.8 CRITICAL
Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
CVE-2024-53364 1 Phpgurukul 1 Vehicle Parking Management System 2026-07-05 N/A 5.4 MEDIUM
A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.
CVE-2024-52725 1 Sem-cms 1 Semcms 2026-07-05 N/A 4.9 MEDIUM
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
CVE-2024-51065 1 Phpgurukul 1 Beauty Parlour Management System 2026-07-05 N/A 9.8 CRITICAL
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
CVE-2024-51064 1 Phpgurukul 1 Teachers Record Management System 2026-07-05 N/A 9.8 CRITICAL
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.
CVE-2024-51063 1 Phpgurukul 1 Teachers Record Management System 2026-07-05 N/A 9.1 CRITICAL
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.
CVE-2024-51060 1 Projectworlds 1 Online Admission System 2026-07-05 N/A 9.1 CRITICAL
Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.
CVE-2024-50942 2026-07-05 N/A 9.8 CRITICAL
qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.
CVE-2024-48245 1 Janobe 1 Vehicle Management System 2026-07-05 N/A 7.2 HIGH
Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which are present in /newvehicle.php and /newdriver.php.