Vulnerabilities (CVE)

Filtered by CWE-89
Total 20704 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-66658 2026-08-14 N/A 8.5 HIGH
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
CVE-2026-66472 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
CVE-2026-66478 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
CVE-2026-28142 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
CVE-2026-66436 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
CVE-2026-28001 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-28156 2026-08-14 N/A 8.5 HIGH
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-61966 2026-08-14 N/A 9.3 CRITICAL
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
CVE-2026-28002 2026-08-14 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22.
CVE-2026-66430 2026-08-14 N/A 8.5 HIGH
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66446 2026-08-14 N/A 9.3 CRITICAL
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
CVE-2026-61969 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
CVE-2026-27538 2026-08-14 N/A 7.5 HIGH
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-28168 2026-08-14 N/A 8.5 HIGH
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVE-2026-66458 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
CVE-2026-73663 2026-08-14 N/A N/A
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.
CVE-2026-19351 2026-08-13 7.5 HIGH 7.3 HIGH
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.
CVE-2026-17222 1 Ibm 1 I 2026-08-13 N/A 4.3 MEDIUM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command.
CVE-2026-17418 1 Ibm 1 I 2026-08-13 N/A 8.5 HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
CVE-2026-34185 1 Hydrosystem.poznan 1 Control System 2026-08-13 N/A 8.8 HIGH
AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This issue was fixed in AlanWeb SCADA version 9.8.5