← Back to feed Search feed

CWE-89 SQL Injection vulnerabilities

116 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-48330Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL CRITICAL10.049%ileNVD2026-08-03
CVE-2026-52887NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCECRITICAL10.045%ileGitHub2026-07-31
CVE-2026-63232A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject throCRITICAL9.922%ileNVD2026-07-29
CVE-2026-63233A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject throCRITICAL9.922%ileNVD2026-07-29
CVE-2026-63234A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject throCRITICAL9.922%ileNVD2026-07-29
CVE-2026-58046Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injectCRITICAL9.927%ileNVD2026-07-30
CVE-2026-69083SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachableCRITICAL9.928%ileNVD2026-08-03
CVE-2026-69084SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statementCRITICAL9.921%ileNVD2026-08-03
CVE-2026-69085SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-sCRITICAL9.916%ileNVD2026-08-03
CVE-2026-48326Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL CRITICAL9.939%ileNVD2026-08-03
CVE-2026-54658Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/uCRITICAL9.832%ileNVD2026-07-28
CVE-2025-65340kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.CRITICAL9.818%ileNVD2026-07-29
CVE-2025-67403Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameteCRITICAL9.818%ileNVD2026-07-29
CVE-2025-67404Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters CRITICAL9.818%ileNVD2026-07-29
CVE-2025-69942kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.CRITICAL9.818%ileNVD2026-07-29
CVE-2025-69943kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and CRITICAL9.820%ileNVD2026-07-29
CVE-2026-4978Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision TraffiCRITICAL9.818%ileNVD2026-07-30
CVE-2025-65336Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.CRITICAL9.824%ileNVD2026-07-30
CVE-2025-69930CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.CRITICAL9.818%ileNVD2026-07-30
CVE-2025-69931CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.CRITICAL9.818%ileNVD2026-07-30
CVE-2025-69933CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.CRITICAL9.818%ileNVD2026-07-30
CVE-2025-69934CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.CRITICAL9.818%ileNVD2026-07-30
CVE-2025-69935CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via thCRITICAL9.818%ileNVD2026-07-30
CVE-2025-69936CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.CRITICAL9.818%ileNVD2026-07-30
CVE-2025-69937CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the ParameteCRITICAL9.818%ileNVD2026-07-30
CVE-2025-69938CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.CRITICAL9.818%ileNVD2026-07-30
CVE-2025-69941SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.CRITICAL9.818%ileNVD2026-07-30
CVE-2025-69947SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.CRITICAL9.818%ileNVD2026-07-30
CVE-2025-69946SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distrCRITICAL9.826%ileNVD2026-07-31
CVE-2025-69948SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.CRITICAL9.823%ileNVD2026-07-31
CVE-2026-69240Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oraclCRITICAL9.824%ileNVD2026-08-03
CVE-2026-15721Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST DigCRITICAL9.814%ileNVD2026-08-04
CVE-2026-6881A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated aCRITICAL9.410%ileNVD2026-07-28
CVE-2026-63221CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound vCRITICAL9.430%ileNVD2026-07-31
CVE-2026-17351The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_quCRITICAL9.437%ileNVD2026-07-31
CVE-2026-58048Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.CRITICAL9.440%ileNVD2026-07-31
CVE-2025-67649A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input CRITICAL9.320%ileNVD2026-07-31
CVE-2026-65321PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrarCRITICAL9.336%ileNVD2026-08-02
CVE-2026-18801OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution CRITICAL9.3NVD2026-08-04
CVE-2026-65890Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unautheCRITICAL9.215%ileNVD2026-07-29
CVE-2026-63229A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-CRITICAL9.122%ileNVD2026-07-29
CVE-2026-63230A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read CRITICAL9.122%ileNVD2026-07-29
CVE-2026-51992SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary codeCRITICAL9.141%ileNVD2026-07-29
CVE-2026-13596The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameteCRITICAL9.118%ileNVD2026-08-01
CVE-2026-12965The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action befoCRITICAL9.125%ileNVD2026-08-03
CVE-2026-16532The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using CRITICAL9.118%ileNVD2026-08-03
CVE-2026-50736The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscribCRITICAL9.09%ileNVD2026-07-28
CVE-2026-5490DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate priviHIGH8.839%ileNVD2026-07-29
CVE-2026-6637PostgreSQL refint allows stack buffer overflow and SQL injectionHIGH8.830%ileMicrosoft2026-05-12
CVE-2026-8339A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusHIGH8.710%ileNVD2026-07-29
CVE-2026-54368CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allowsHIGH8.732%ileNVD2026-07-30
CVE-2026-17346The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatinHIGH8.736%ileNVD2026-07-31
CVE-2026-41453Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated useHIGH8.728%ileNVD2026-08-03
CVE-2026-48448Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL HIGH8.630%ileNVD2026-07-30
CVE-2026-13395The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a HIGH8.626%ileNVD2026-07-30
CVE-2026-22620Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauHIGH8.629%ileNVD2026-07-30
CVE-2026-12721The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before usHIGH8.618%ileNVD2026-07-31
CVE-2025-67650An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatioHIGH8.620%ileNVD2026-07-31
CVE-2026-46593A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of inputHIGH8.622%ileNVD2026-07-31
CVE-2026-16572The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in aHIGH8.620%ileNVD2026-08-03
CVE-2026-39931OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature tHIGH8.625%ileNVD2026-08-03
CVE-2026-64631A vulnerability allowing a low-privileged user to inject SQL and extract database contents.HIGH8.5NVD2026-08-04
CVE-2026-7769IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM HIGH8.120%ileNVD2026-07-28
CVE-2026-63231A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-basedHIGH8.117%ileNVD2026-07-29
CVE-2026-17543Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions fHIGH8.131%ileNVD2026-07-30
CVE-2026-15258The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feHIGH8.113%ileNVD2026-07-31
CVE-2026-16539The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SHIGH8.113%ileNVD2026-08-03
CVE-2025-67405Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the paramHIGH7.37%ileNVD2026-07-29
CVE-2025-67406https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execuHIGH7.310%ileNVD2026-07-29
CVE-2025-67407Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parametersHIGH7.37%ileNVD2026-07-29
CVE-2025-67408Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter HIGH7.37%ileNVD2026-07-29
CVE-2025-69945kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.HIGH7.37%ileNVD2026-07-29
CVE-2025-69949kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emHIGH7.37%ileNVD2026-07-29
CVE-2026-12895SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queriesHIGH7.112%ileNVD2026-07-29
CVE-2026-15929Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmaHIGH7.17%ileNVD2026-07-30
CVE-2026-18737Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQLHIGH7.115%ileNVD2026-08-03
CVE-2026-39879SQL injection in syslog-ng SQL destionation driverHIGH7.17%ileMicrosoft2026-07-14
CVE-2026-15153The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative MEDIUM6.822%ileNVD2026-07-30
CVE-2026-48121@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for stoMEDIUM6.7NVD2026-08-04
CVE-2026-15304The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions MEDIUM6.516%ileNVD2026-07-28
CVE-2026-16092The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field viMEDIUM6.516%ileNVD2026-07-30
CVE-2026-14554The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using themMEDIUM6.514%ileNVD2026-07-31
CVE-2026-16087The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL InjecMEDIUM6.519%ileNVD2026-08-01
CVE-2026-6453The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. ThiMEDIUM6.520%ileNVD2026-08-01
CVE-2026-11391Tanium addressed a SQL injection vulnerability in Patch.MEDIUM6.38%ileNVD2026-07-28
CVE-2024-36039PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dictMEDIUM6.349%ileMicrosoft2024-05-14
CVE-2026-45376Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3MEDIUM5.527%ileNVD2026-07-31
CVE-2026-15018The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorMEDIUM5.318%ileNVD2026-08-01
CVE-2026-33385A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a higMEDIUM5.115%ileNVD2026-07-29
CVE-2026-15344The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all verMEDIUM4.928%ileNVD2026-07-29
CVE-2026-11973The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in aMEDIUM4.922%ileNVD2026-07-29
CVE-2026-15403The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameMEDIUM4.919%ileNVD2026-08-01
CVE-2026-15951The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, andMEDIUM4.919%ileNVD2026-08-01
CVE-2026-16614The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL MEDIUM4.919%ileNVD2026-08-01
CVE-2026-17555The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in versMEDIUM4.919%ileNVD2026-08-01
CVE-2026-62845Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivMEDIUM4.710%ileNVD2026-07-30
CVE-2026-15381The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SLOW3.78%ileNVD2026-07-31
CVE-2026-6638PostgreSQL REFRESH PUBLICATION allows SQL injection via table nameLOW3.78%ileMicrosoft2026-05-12
CVE-2026-18719A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compoLOW2.19%ileNVD2026-08-04
CVE-2026-18766A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affectLOW2.1NVD2026-08-04
CVE-2026-18592A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of LOW2.010%ileNVD2026-08-03
CVE-2025-69944kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vieUNKNOWN4%ileNVD2026-07-29
CVE-2026-51775SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicatiUNKNOWN4%ileNVD2026-08-03
CVE-2026-52521A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via thUNKNOWN4%ileNVD2026-08-03
CVE-2026-14872The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and eUNKNOWN5%ileNVD2026-08-04
CVE-2026-70369Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-conUNKNOWNNVD2026-08-04
CVE-2026-70370Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and ColuUNKNOWNNVD2026-08-04
CVE-2026-70371Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request UNKNOWNNVD2026-08-04
CVE-2026-70372Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request paUNKNOWNNVD2026-08-04
CVE-2026-70373Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concUNKNOWNNVD2026-08-04
CVE-2026-41889pgx: SQL Injection via placeholder confusion with dollar quoted string literalsUNKNOWN28%ileMicrosoft2026-05-12
CVE-2025-14179SQL injection in pdo_firebird via NUL bytes in quoted stringsUNKNOWN36%ileMicrosoft2026-05-12
Security Advisory 0145Security Advisory 0145UNKNOWNArista2026-07-27
FG-IR-26-132SQL command injection in administrative portalUNKNOWNFortinet2026-05-12
FG-IR-26-134User controlled SQL commandsUNKNOWNFortinet2026-05-12
FG-IR-26-102Multiple SQL InjectionsUNKNOWNFortinet2026-04-14