Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-40826 1 Codeigniter 1 Codeigniter 2026-06-17 N/A 9.8 CRITICAL
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
CVE-2022-40825 1 Codeigniter 1 Codeigniter 2026-06-17 N/A 9.8 CRITICAL
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
CVE-2022-40824 1 Codeigniter 1 Codeigniter 2026-06-17 N/A 9.8 CRITICAL
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
CVE-2022-40766 1 Moderncampus 1 Omni Cms 2026-06-17 N/A 9.8 CRITICAL
Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring.
CVE-2022-40615 2 Ibm, Linux 2 Sterling Partner Engagement Manager, Linux Kernel 2026-06-17 N/A 6.3 MEDIUM
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208.
CVE-2022-40485 1 Wedding Planner Project 1 Wedding Planner 2026-06-17 N/A 9.8 CRITICAL
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.
CVE-2022-40484 1 Wedding Planner Project 1 Wedding Planner 2026-06-17 N/A 9.8 CRITICAL
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.
CVE-2022-40483 1 Wedding Planner Project 1 Wedding Planner 2026-06-17 N/A 9.8 CRITICAL
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.
CVE-2022-40447 1 Zzcms 1 Zzcms 2026-06-17 N/A 7.2 HIGH
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
CVE-2022-40446 1 Zzcms 1 Zzcms 2026-06-17 N/A 7.2 HIGH
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.
CVE-2022-40405 1 Wowonder 1 Wowonder 2026-06-17 N/A 7.5 HIGH
WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs.
CVE-2022-40404 1 Wedding Planner Project 1 Wedding Planner 2026-06-17 N/A 8.8 HIGH
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.
CVE-2022-40403 1 Wedding Planner Project 1 Wedding Planner 2026-06-17 N/A 7.2 HIGH
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.
CVE-2022-40402 1 Wedding Planner Project 1 Wedding Planner 2026-06-17 N/A 8.8 HIGH
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.
CVE-2022-40354 1 Online Tours \& Travels Management System Project 1 Online Tours \& Travels Management System 2026-06-17 N/A 7.2 HIGH
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.
CVE-2022-40353 1 Online Tours \& Travels Management System Project 1 Online Tours \& Travels Management System 2026-06-17 N/A 7.2 HIGH
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php.
CVE-2022-40352 1 Online Tours \& Travels Management System Project 1 Online Tours \& Travels Management System 2026-06-17 N/A 7.2 HIGH
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_traveller.php.
CVE-2022-40347 1 Intern Record System Project 1 Intern Record System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.
CVE-2022-40315 2 Fedoraproject, Moodle 3 Extra Packages For Enterprise Linux, Fedora, Moodle 2026-06-17 N/A 9.8 CRITICAL
A limited SQL injection risk was identified in the "browse list of users" site administration page.
CVE-2022-40300 1 Zohocorp 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro 2026-06-17 N/A 9.8 CRITICAL
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.