Vulnerabilities (CVE)

Filtered by CWE-89
Total 19990 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-13555 2026-06-29 7.5 HIGH 7.3 HIGH
A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
CVE-2026-13525 2026-06-29 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
CVE-2026-13531 2026-06-29 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /department.php. The manipulation of the argument editid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
CVE-2026-13331 2026-06-29 N/A 6.5 MEDIUM
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with marketer-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-13333 2026-06-29 N/A 6.5 MEDIUM
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Sales Representative-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The sanitized Contact_Query code path can be bypassed by supplying an invalid filter type (e.g., query[filters][0][0][type]=invalid_filter_nonexistent), causing a FilterException to be caught and execution to fall through to the unsanitized Legacy_Contact_Query path.
CVE-2025-20272 1 Cisco 2 Evolved Programmable Network Manager, Prime Infrastructure 2026-06-29 N/A 4.3 MEDIUM
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
CVE-2026-57642 2026-06-29 N/A 8.5 HIGH
Contributor SQL Injection in Gallery <= 4.7.8 versions.
CVE-2026-56034 2026-06-29 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
CVE-2026-52785 2026-06-29 N/A 9.9 CRITICAL
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This vulnerability is fixed in 17.3.3 and 17.4.1.
CVE-2026-57667 2026-06-29 N/A 8.5 HIGH
Sales Representative SQL Injection in Groundhogg <= 4.5 versions.
CVE-2026-56068 2026-06-29 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
CVE-2026-12050 1 Pgadmin 1 Pgadmin 4 2026-06-29 N/A 4.3 MEDIUM
SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a bound parameter, allowing an authenticated pgAdmin user with a connected PostgreSQL session to inject additional statements through that endpoint. The injected SQL executes under the database role the user is already authenticated as. The defect does not cross a privilege boundary -- the user already has direct SQL access to that role through the Query Tool -- so the attacker gains no capability beyond what their database role already grants them. The marginal impact accounts for the fact that the injection path is not the documented SQL-execution interface, so a deployment that gates the Query Tool at the application layer could see SQL executed through a path it did not anticipate. Fix passes the restore point name as a bound parameter and schema-qualifies the function call as pg_catalog.pg_create_restore_point so a non-default search_path on the connection cannot redirect the call to a shadow definition. A regression test asserts the value arrives as a bound parameter and not spliced into the SQL string. This issue affects pgAdmin 4: from 1.0 before 9.16.
CVE-2026-57643 2026-06-26 N/A 8.5 HIGH
Contributor SQL Injection in WP Post Author <= 3.9.1 versions.
CVE-2026-57636 2026-06-26 N/A 8.5 HIGH
Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.
CVE-2026-56062 2026-06-26 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.
CVE-2026-54827 2026-06-26 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
CVE-2026-39951 1 Cacti 1 Cacti 2026-06-26 N/A 7.6 HIGH
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports feature. This issue has been fixed in version 1.2.31.
CVE-2026-44271 1 Dell 1 Wyse Management Suite 2026-06-26 N/A 8.1 HIGH
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-44272 1 Dell 1 Wyse Management Suite 2026-06-26 N/A 8.8 HIGH
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-57663 2026-06-26 N/A 8.5 HIGH
Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.