Vulnerabilities (CVE)

Filtered by CWE-89
Total 20765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26745 1 Opensourcepos 1 Open Source Point Of Sale 2026-06-17 N/A 5.3 MEDIUM
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This allows an attacker with access to modify the currency_symbol value to inject arbitrary SQL expressions, which are executed when the affected query is subsequently processed.
CVE-2026-26713 1 Carmelo 1 Simple Food Order System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.
CVE-2026-26712 1 Carmelo 1 Simple Food Order System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.
CVE-2026-26711 1 Carmelo 1 Simple Food Order System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.
CVE-2026-26710 1 Carmelo 1 Simple Food Order System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.
CVE-2026-26709 1 Carmelo 1 Simple Gym Management System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.
CVE-2026-26708 1 Oretnom23 1 Pharmacy Point Of Sale System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.
CVE-2026-26707 1 Oretnom23 1 Pharmacy Point Of Sale System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.
CVE-2026-26706 1 Oretnom23 1 Pharmacy Point Of Sale System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.
CVE-2026-26705 1 Oretnom23 1 Pharmacy Point Of Sale System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.
CVE-2026-26704 1 Oretnom23 1 Pharmacy Point Of Sale System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.
CVE-2026-26703 1 Jon-remus-sevellejo 1 Personnel Property Equipment System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php.
CVE-2026-26702 1 Jon-remus-sevellejo 1 Personnel Property Equipment System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php.
CVE-2026-26701 1 Jon-remus-sevellejo 1 Personnel Property Equipment System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php.
CVE-2026-26700 1 Jon-remus-sevellejo 1 Personnel Property Equipment System 2026-06-17 N/A 9.8 CRITICAL
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php.
CVE-2026-26698 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 4.9 MEDIUM
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.
CVE-2026-26697 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 4.9 MEDIUM
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?teacherID=.
CVE-2026-26696 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.
CVE-2026-26695 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
CVE-2026-26694 1 Carmelo 1 Simple Student Alumni System 2026-06-17 N/A 9.8 CRITICAL
code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.