Vulnerabilities (CVE)

Filtered by CWE-89
Total 20733 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-26624 1 Gilacms 1 Gila Cms 2026-07-09 N/A 3.8 LOW
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
CVE-2020-26623 1 Gilacms 1 Gila Cms 2026-07-09 N/A 3.8 LOW
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
CVE-2020-25514 1 Simple Library Management System Project 1 Simple Library Management System 2026-07-09 4.6 MEDIUM 8.4 HIGH
Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://<site>/lms/admin.php.
CVE-2020-25487 1 Phpgurukul 1 Zoo Management System 2026-07-09 4.6 MEDIUM 7.8 HIGH
PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.
CVE-2020-24913 1 Qcubed 1 Qcubed 2026-07-09 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
CVE-2020-24841 1 Sdg 1 Pnpscada 2026-07-09 7.5 HIGH 9.8 CRITICAL
PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
CVE-2020-24193 1 Daily Tracker System Project 1 Daily Tracker System 2026-07-09 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.
CVE-2020-23630 1 Zzcms 1 Zzcms 2026-07-09 6.5 MEDIUM 8.8 HIGH
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
CVE-2020-22452 1 Phpmyadmin 1 Phpmyadmin 2026-07-09 N/A 9.8 CRITICAL
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
CVE-2020-22168 1 Phpgurukul 1 Hospital Management System 2026-07-09 5.0 MEDIUM 7.5 HIGH
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2020-20585 1 Metinfo 1 Metinfo 2026-07-09 5.0 MEDIUM 7.5 HIGH
A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.
CVE-2020-19961 1 Zzcms 1 Zzcms 2026-07-09 5.0 MEDIUM 7.5 HIGH
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.
CVE-2026-12936 2026-07-08 N/A 4.9 MEDIUM
The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-6854 2026-07-08 N/A 7.5 HIGH
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-6230 2026-07-08 N/A 7.5 HIGH
The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-9700 2026-07-08 N/A 7.5 HIGH
The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-42475 1 Openmix 1 Mix Php 2026-07-08 N/A 6.5 MEDIUM
SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHelper.php.
CVE-2026-58521 1 Mediawiki 2 Cargo, Mediawiki 2026-07-07 N/A 9.8 CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.
CVE-2026-14363 1 Mediawiki 2 Cargo, Mediawiki 2026-07-07 N/A 9.8 CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.
CVE-2026-9272 1 Progress 1 Flowmon Anomaly Detection System 2026-07-07 N/A 8.1 HIGH
In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.