Vulnerabilities (CVE)

Filtered by CWE-89
Total 20734 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-70397 1 Jizhicms 1 Jizhicms 2026-07-05 N/A 7.2 HIGH
jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.
CVE-2025-60641 2026-07-05 N/A 6.5 MEDIUM
The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexcel'])), where $_POST['mexcel'] is user-controlled input. This input is decoded from base64 and deserialized without validation or use of the allowed_classes option, allowing an attacker to inject arbitrary PHP objects. This can lead to malicious behavior, such as Remote Code Execution (RCE), SQL Injection, Path Traversal, or Denial of Service, depending on the availability of exploitable classes in the Vfront codebase or its dependencies.
CVE-2025-60307 1 Carmelo 1 Computer Laboratory System 2026-07-05 N/A 9.8 CRITICAL
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.
CVE-2025-56421 1 Limesurvey 1 Limesurvey 2026-07-05 N/A 7.5 HIGH
SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.
CVE-2025-56401 1 Ziragroup 1 Wbrm 2026-07-05 N/A 7.6 HIGH
ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
CVE-2025-55849 1 Weiphp 1 Weiphp 2026-07-05 N/A 8.4 HIGH
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
CVE-2025-52025 1 Aptsys 1 Gemscms Backend 2026-07-05 N/A 9.4 CRITICAL
An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or parameterization. This allows an attacker to inject and execute arbitrary SQL code by submitting crafted input in the id parameter, leading to unauthorized data access or modification.
CVE-2025-51683 1 Mjobtime 1 Mjobtime 2026-07-05 N/A 9.8 CRITICAL
A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .
CVE-2025-50383 1 Easyappointments 1 Easy\!appointments 2026-07-05 N/A 8.1 HIGH
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
CVE-2023-49440 2026-07-05 N/A 8.8 HIGH
AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."
CVE-2025-52327 1 Carmelogarcia 1 Restaurant Order System 2026-07-05 N/A 7.8 HIGH
SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file
CVE-2025-51660 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
CVE-2025-51659 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.
CVE-2025-51658 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
CVE-2025-51657 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
CVE-2025-51656 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
CVE-2025-51655 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
CVE-2025-51654 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
CVE-2025-51653 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
CVE-2025-51652 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.