Vulnerabilities (CVE)

Filtered by CWE-89
Total 20736 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-51653 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
CVE-2025-51652 1 Sem-cms 1 Semcms 2026-07-05 N/A 5.4 MEDIUM
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.
CVE-2025-50585 1 Daycloud 1 Studentmanage 2026-07-05 N/A 8.8 HIGH
StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.
CVE-2025-50341 2026-07-05 N/A 9.8 CRITICAL
A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.
CVE-2025-44608 1 Vishalmathur 1 Cloudclassroom-php Project 2026-07-05 N/A 6.5 MEDIUM
CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.
CVE-2024-55160 1 G-fast 1 Gfast 2026-07-05 N/A 9.8 CRITICAL
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.
CVE-2024-53480 1 Phpgurukul 1 Beauty Parlour Management System 2026-07-05 N/A 9.8 CRITICAL
Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
CVE-2024-53364 1 Phpgurukul 1 Vehicle Parking Management System 2026-07-05 N/A 5.4 MEDIUM
A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.
CVE-2024-52725 1 Sem-cms 1 Semcms 2026-07-05 N/A 4.9 MEDIUM
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
CVE-2024-51065 1 Phpgurukul 1 Beauty Parlour Management System 2026-07-05 N/A 9.8 CRITICAL
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
CVE-2024-51064 1 Phpgurukul 1 Teachers Record Management System 2026-07-05 N/A 9.8 CRITICAL
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.
CVE-2024-51063 1 Phpgurukul 1 Teachers Record Management System 2026-07-05 N/A 9.1 CRITICAL
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.
CVE-2024-51060 1 Projectworlds 1 Online Admission System 2026-07-05 N/A 9.1 CRITICAL
Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.
CVE-2024-50942 2026-07-05 N/A 9.8 CRITICAL
qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.
CVE-2024-48245 1 Janobe 1 Vehicle Management System 2026-07-05 N/A 7.2 HIGH
Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which are present in /newvehicle.php and /newdriver.php.
CVE-2024-46532 2026-07-05 N/A 9.8 CRITICAL
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.
CVE-2024-45955 1 Rocketsoftware 1 Zena 2026-07-05 N/A 7.3 HIGH
Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
CVE-2021-37291 1 Kevinlab 1 4st L-bems 2026-07-05 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
CVE-2024-53597 2026-07-04 N/A 6.3 MEDIUM
masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.
CVE-2026-57765 2026-07-02 N/A 8.5 HIGH
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.