Vulnerabilities (CVE)

Filtered by CWE-89
Total 20691 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-66594 2026-08-20 N/A 8.5 HIGH
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
CVE-2026-61518 2026-08-20 N/A 8.8 HIGH
ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection scanner does not block quote-free boolean payloads and does not reject requests in its default configuration. A remote API user holding any single low-privilege function permission can inject arbitrary SQL to delete or modify records across all tenants in the control panel database and extract arbitrary data via blind boolean inference, including password hashes and client records.
CVE-2026-73998 2026-08-20 N/A 8.5 HIGH
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
CVE-2026-66592 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVE-2026-20327 2026-08-20 N/A 6.5 MEDIUM
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database&nbsp;of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
CVE-2026-20030 2026-08-20 N/A 10.0 CRITICAL
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used in a SQL command issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89.
CVE-2026-32552 2026-08-20 N/A 8.5 HIGH
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
CVE-2026-73183 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
CVE-2026-73391 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
CVE-2026-19926 2026-08-20 7.5 HIGH 7.3 HIGH
A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder OpenSRF Service. Such manipulation leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 is sufficient to fix this issue. The affected component should be upgraded.
CVE-2026-76050 2026-08-20 7.5 HIGH 7.3 HIGH
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVE-2026-75080 2026-08-20 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-73388 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
CVE-2026-75876 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Move Operations. Such manipulation of the argument sourcePath leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-73339 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
CVE-2026-74015 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
CVE-2026-75088 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument delid can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-73365 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
CVE-2026-66622 2026-08-20 N/A 7.5 HIGH
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
CVE-2026-19934 2026-08-20 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument delid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.