Vulnerabilities (CVE)

Filtered by CWE-89
Total 20784 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-26136 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.
CVE-2025-26086 1 Rsiqueue 1 Management System 2026-06-17 N/A 7.5 HIGH
An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of sensitive database contents without authentication.
CVE-2025-26047 1 Olajowon 1 Loggrove 2026-06-17 N/A 5.1 MEDIUM
Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.
CVE-2025-25994 1 Feminer Wms Project 1 Feminer Wms 2026-06-17 N/A 7.5 HIGH
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.
CVE-2025-25993 1 Feminer Wms Project 1 Feminer Wms 2026-06-17 N/A 5.1 MEDIUM
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."
CVE-2025-25992 1 Feminer Wms Project 1 Feminer Wms 2026-06-17 N/A 5.1 MEDIUM
SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.
CVE-2025-25991 1 Hoosk 1 Hoosk 2026-06-17 N/A 5.1 MEDIUM
SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
CVE-2025-25914 1 Carmelo 1 Online Exam Mastering System 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter
CVE-2025-25878 1 Angeljudesuarez 1 Simple Chatbox 2026-06-17 N/A 3.8 LOW
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The attack can use SQL injection to obtain sensitive data.
CVE-2025-25877 1 Angeljudesuarez 1 Simple Chatbox 2026-06-17 N/A 3.8 LOW
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /admin.php. The attack can use SQL injection to obtain sensitive data.
CVE-2025-25876 1 Angeljudesuarez 1 Simple Chatbox 2026-06-17 N/A 7.2 HIGH
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /delete.php. The attack can use SQL injection to obtain sensitive data.
CVE-2025-25875 1 Angeljudesuarez 1 Simple Chatbox 2026-06-17 N/A 6.4 MEDIUM
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The attack can use SQL injection to obtain sensitive data.
CVE-2025-25775 1 Codeastro 1 Bus Ticket Booking System 2026-06-17 N/A 9.8 CRITICAL
Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
CVE-2025-25763 1 Crmeb 1 Crmeb 2026-06-17 N/A 9.8 CRITICAL
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
CVE-2025-25686 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
CVE-2025-25590 1 R1bbit 1 Yimioa 2026-06-17 N/A 6.1 MEDIUM
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.
CVE-2025-25582 1 R1bbit 1 Yimioa 2026-06-17 N/A 6.1 MEDIUM
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml.
CVE-2025-25580 1 R1bbit 1 Yimioa 2026-06-17 N/A 6.1 MEDIUM
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.
CVE-2025-25521 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
CVE-2025-25520 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.