Vulnerabilities (CVE)

Filtered by CWE-89
Total 20784 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-29647 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
CVE-2025-29641 1 Anujk305 1 Vehicle Record Management System 2026-06-17 N/A 7.3 HIGH
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' parameter.
CVE-2025-29640 1 Anujk305 1 Human Metapneumovirus \(hmpv\) - Testing Management System 2026-06-17 N/A 5.4 MEDIUM
Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-report.php via the parameter searchdata..
CVE-2025-29529 2026-06-17 N/A 6.5 MEDIUM
ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.
CVE-2025-29425 1 Fabian 1 Online Class And Exam Scheduling System 2026-06-17 N/A 5.5 MEDIUM
Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.
CVE-2025-29391 1 Horvey 1 Library-manager 2026-06-17 N/A 7.2 HIGH
horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php.
CVE-2025-29390 1 Jerryhanjj 1 Erp 2026-06-17 N/A 8.8 HIGH
jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.
CVE-2025-29369 1 Carmelogarcia 1 Matrimonial Site 2026-06-17 N/A 9.8 CRITICAL
Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1.
CVE-2025-29208 1 Codezips 1 Gym Management System 2026-06-17 N/A 6.5 MEDIUM
CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.
CVE-2025-29189 1 Flowiseai 1 Flowise 2026-06-17 N/A 7.6 HIGH
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.
CVE-2025-29181 1 Foxcms 1 Foxcms 2026-06-17 N/A 7.2 HIGH
FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.
CVE-2025-29180 1 Foxcms 1 Foxcms 2026-06-17 N/A 7.2 HIGH
In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.
CVE-2025-29153 1 Lemeconsultoria 1 Galera 2026-06-17 N/A 5.4 MEDIUM
SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export, filters functions.
CVE-2025-29085 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component.
CVE-2025-29084 1 Cszcms 1 Csz Cms 2026-06-17 N/A 6.5 MEDIUM
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Upgrade.php file.
CVE-2025-28983 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8.
CVE-2025-28982 1 Thimpress 1 Wp Pipes 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3.
CVE-2025-28972 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Suhas Surse WP Employee Attendance System wp-employee-attendance-system allows Blind SQL Injection.This issue affects WP Employee Attendance System: from n/a through <= 3.5.
CVE-2025-28969 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widget gallery-widget allows SQL Injection.This issue affects Gallery Widget: from n/a through <= 1.2.1.
CVE-2025-28967 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LITE contact-us-page-contact-people allows SQL Injection.This issue affects Contact Us page - Contact people LITE: from n/a through <= 3.7.4.