CVE z tagiem sql-injection — 200 wyników. ← Wszystkie tagi

CVE-2026-9082 🔴 Łataj teraz KEV
apps

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 befor…

9.8 CVSS
88.3% EPSS
drupalsql-injection 2026-05-20
CVE-2026-60137 🔴 Łataj teraz KEV
apps

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input …

5.9 CVSS
78.0% EPSS
CVE-2016-2386 🔴 Łataj teraz KEV

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

9.8 CVSS
44.5% EPSS
CVE-2026-21643 🔴 Łataj teraz KEV
network

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via sp…

9.8 CVSS
33.9% EPSS
CVE-2020-29574 🔴 Łataj teraz KEV

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

9.8 CVSS
4.7% EPSS
sophossql-injection 2020-12-11
CVE-2014-2323 🔴 Łataj teraz
os

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

9.8 CVSS
90.4% EPSS
CVE-2023-5204 🔴 Łataj teraz

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat…

9.8 CVSS
87.0% EPSS
CVE-2022-1768 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. …

9.8 CVSS
86.1% EPSS
CVE-2022-1453 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it…

9.8 CVSS
62.1% EPSS
CVE-2013-4467 ⚪ Do wiadomości

Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the ca…

6.5 CVSS
78.3% EPSS
CVE-2024-49681 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Se…

9.3 CVSS
51.3% EPSS
sql-injection 2024-10-24
CVE-2014-0763 🟡 Monitoruj

An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll is exposed through SOAP interfaces, and the exposed functions are vulnerable to SOAP injection. Thi…

7.5 CVSS
57.9% EPSS
CVE-2020-24913 🔴 Łataj teraz

A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

9.8 CVSS
40.6% EPSS
CVE-2023-3197 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lac…

9.8 CVSS
36.8% EPSS
CVE-2024-50491 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

9.3 CVSS
37.7% EPSS
CVE-2022-44588 🔴 Łataj teraz

Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

9.9 CVSS
34.0% EPSS
CVE-2022-45805 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a thr…

8.2 CVSS
39.4% EPSS
paytmsql-injection 2023-11-03
CVE-2023-28787 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

9.3 CVSS
32.0% EPSS
sql-injection 2024-03-26
CVE-2014-2238 ⚪ Do wiadomości

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id…

6.5 CVSS
45.4% EPSS
CVE-2024-2387 ⚪ Do wiadomości

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, an…

6.1 CVSS
36.6% EPSS
sql-injection 2024-03-20
CVE-2023-32590 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a thro…

9.3 CVSS
19.3% EPSS
CVE-2023-50839 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support…

9.3 CVSS
16.3% EPSS
CVE-2023-24000 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through 2.5.7.

8.2 CVSS
21.2% EPSS
CVE-2017-5611 🟠 Łataj w tym tygodniu
appsos

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that…

9.8 CVSS
12.4% EPSS
oraclesql-injection 2017-01-30
CVE-2022-36635 🟠 Łataj w tym tygodniu

ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.

8.8 CVSS
16.6% EPSS
CVE-2023-3047 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection.This issue affects Lockcell: before 15.

9.8 CVSS
9.0% EPSS
CVE-2026-63030 🟠 Łataj w tym tygodniu

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker …

9.8 CVSS
8.9% EPSS
rcesql-injection 2026-07-17
CVE-2021-37291 🔴 Łataj teraz

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

9.8 CVSS
8.2% EPSS
CVE-2026-47992 🟡 Monitoruj

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high…

7.2 CVSS
19.9% EPSS
CVE-2022-27984 🔴 Łataj teraz

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

9.8 CVSS
6.7% EPSS
CVE-2022-27985 🔴 Łataj teraz

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

9.8 CVSS
6.7% EPSS
CVE-2006-5344 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_3gl, aka Vu…

9.0 CVSS
10.5% EPSS
CVE-2026-3018 🟡 Monitoruj

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the user supplied parameter …

7.5 CVSS
17.6% EPSS
sql-injection 2026-06-10
CVE-2023-45657 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.

8.5 CVSS
12.2% EPSS
CVE-2026-23696 🟠 Łataj w tym tygodniu

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. A…

9.9 CVSS
5.1% EPSS
sql-injection 2026-04-07
CVE-2023-5412 🟠 Łataj w tym tygodniu

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter…

8.8 CVSS
9.8% EPSS
CVE-2015-8974 🟠 Łataj w tym tygodniu

SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execu…

10.0 CVSS
3.7% EPSS
mybbsql-injection 2017-01-31
CVE-2023-34752 🔴 Łataj teraz
os

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

9.8 CVSS
4.4% EPSS
CVE-2012-10047 ⚪ Do wiadomości

Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to in…

0.0 CVSS
53.2% EPSS
rcesql-injection 2025-08-08
CVE-2016-9402 🟠 Łataj w tym tygodniu

SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

9.8 CVSS
3.7% EPSS
mybbsql-injection 2017-01-31
CVE-2016-9416 🟠 Łataj w tym tygodniu

SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

9.8 CVSS
3.7% EPSS
mybbsql-injection 2017-01-31
CVE-2022-44290 🔴 Łataj teraz

webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.

9.8 CVSS
3.6% EPSS
CVE-2022-44291 🔴 Łataj teraz

webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.

9.8 CVSS
3.6% EPSS
CVE-2022-1505 🟠 Łataj w tym tygodniu

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This…

9.8 CVSS
3.4% EPSS
CVE-2017-5574 🟠 Łataj w tym tygodniu

SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.

9.8 CVSS
3.4% EPSS
CVE-2017-14851 🟠 Łataj w tym tygodniu

A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack a…

9.8 CVSS
3.1% EPSS
CVE-2021-44088 🔴 Łataj teraz

An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.

CVE-2026-42647 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

9.3 CVSS
5.2% EPSS
sql-injection 2026-06-11
CVE-2006-5675 🟠 Łataj w tym tygodniu

Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors, related to "MySQL Scripts need changes for security," possibly SQL i…

10.0 CVSS
1.6% EPSS
CVE-2020-24193 🔴 Łataj teraz

A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.

CVE-2022-34132 🟠 Łataj w tym tygodniu

Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.

9.8 CVSS
1.9% EPSS
joranisql-injection 2022-06-28
CVE-2024-27304 🟠 Łataj w tym tygodniu

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one …

9.8 CVSS
1.9% EPSS
jackcsql-injection 2024-03-06
CVE-2022-32224 🔴 Łataj teraz

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (vi…

9.8 CVSS
1.8% EPSS
CVE-2020-22452 🔴 Łataj teraz

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

9.8 CVSS
1.7% EPSS
CVE-2026-48330 🟠 Łataj w tym tygodniu

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the curren…

10.0 CVSS
0.7% EPSS
CVE-2026-46670 🟠 Łataj w tym tygodniu

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install t…

9.8 CVSS
1.7% EPSS
sql-injection 2026-08-11
CVE-2022-31382 🔴 Łataj teraz

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

9.8 CVSS
1.6% EPSS
CVE-2022-31383 🔴 Łataj teraz

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

9.8 CVSS
1.6% EPSS
CVE-2022-31384 🔴 Łataj teraz

Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.

9.8 CVSS
1.6% EPSS
CVE-2020-24841 🔴 Łataj teraz

PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in…

9.8 CVSS
1.6% EPSS
CVE-2020-35276 🔴 Łataj teraz

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

9.8 CVSS
1.5% EPSS
CVE-2017-5569 🟠 Łataj w tym tygodniu

An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and wh…

9.8 CVSS
1.4% EPSS
CVE-2026-69083 🟠 Łataj w tym tygodniu

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the …

10.0 CVSS
0.4% EPSS
sql-injection 2026-08-03
CVE-2023-25960 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zen…

10.0 CVSS
0.3% EPSS
CVE-2026-69085 🟠 Łataj w tym tygodniu

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter…

10.0 CVSS
0.3% EPSS
sql-injection 2026-08-03
CVE-2025-4285 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies Agentis allows SQL Injection. This issue affects Agentis: before 4.32.

10.0 CVSS
0.2% EPSS
sql-injection 2025-07-22
CVE-2022-30490 🔴 Łataj teraz

Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.

CVE-2026-34612 🔴 Łataj teraz

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the fo…

9.9 CVSS
0.7% EPSS
CVE-2024-1711 🟠 Łataj w tym tygodniu

The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of suffi…

9.8 CVSS
1.2% EPSS
sql-injection 2024-03-20
CVE-2022-29704 🔴 Łataj teraz

BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.

9.8 CVSS
1.1% EPSS
CVE-2022-35156 🔴 Łataj teraz

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

9.8 CVSS
1.1% EPSS
CVE-2022-31340 🔴 Łataj teraz

Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.

9.8 CVSS
1.1% EPSS
CVE-2024-13152 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery …

10.0 CVSS
0.1% EPSS
sql-injection 2025-02-14
CVE-2022-40030 🔴 Łataj teraz

SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.

CVE-2017-5517 🔴 Łataj teraz

SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.

9.8 CVSS
1.1% EPSS
CVE-2017-5519 🔴 Łataj teraz

SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.

9.8 CVSS
1.1% EPSS
CVE-2026-68782 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

9.9 CVSS
0.5% EPSS
sql-injection 2026-08-20
CVE-2026-68789 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

9.9 CVSS
0.5% EPSS
sql-injection 2026-08-20
CVE-2016-5742 🟠 Łataj w tym tygodniu

SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary S…

9.8 CVSS
1.0% EPSS
CVE-2026-48326 🟠 Łataj w tym tygodniu

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the curren…

9.9 CVSS
0.5% EPSS
CVE-2023-27779 🔴 Łataj teraz

AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.

9.8 CVSS
1.0% EPSS
CVE-2026-40906 🔴 Łataj teraz

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and des…

9.9 CVSS
0.5% EPSS
CVE-2021-39302 🟠 Łataj w tym tygodniu

MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

9.8 CVSS
0.9% EPSS
CVE-2024-46532 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.

9.8 CVSS
0.9% EPSS
sql-injection 2024-10-11
CVE-2022-47770 🔴 Łataj teraz

Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.

9.8 CVSS
0.9% EPSS
CVE-2022-45207 🔴 Łataj teraz

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.

9.8 CVSS
0.9% EPSS
CVE-2022-24240 🟠 Łataj w tym tygodniu

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

9.8 CVSS
0.9% EPSS
CVE-2023-29863 🟠 Łataj w tym tygodniu

Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

9.8 CVSS
0.9% EPSS
CVE-2022-44945 🔴 Łataj teraz

Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.

9.8 CVSS
0.9% EPSS
CVE-2024-37858 🔴 Łataj teraz

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.

9.8 CVSS
0.9% EPSS
CVE-2026-58046 🟠 Łataj w tym tygodniu

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

9.9 CVSS
0.3% EPSS
sql-injection 2026-07-30
CVE-2024-38882 🟠 Łataj w tym tygodniu

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutraliz…

9.8 CVSS
0.8% EPSS
CVE-2021-4340 🔴 Łataj teraz

The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of suff…

9.8 CVSS
0.8% EPSS
CVE-2026-63232 🟠 Łataj w tym tygodniu

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to…

9.9 CVSS
0.3% EPSS
sql-injection 2026-07-29
CVE-2026-63233 🟠 Łataj w tym tygodniu

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell t…

9.9 CVSS
0.3% EPSS
sql-injection 2026-07-29
CVE-2026-63234 🟠 Łataj w tym tygodniu

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a…

9.9 CVSS
0.3% EPSS
sql-injection 2026-07-29
CVE-2023-27202 🔴 Łataj teraz

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.

9.8 CVSS
0.8% EPSS
CVE-2023-27203 🔴 Łataj teraz

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.

9.8 CVSS
0.8% EPSS
CVE-2023-27204 🔴 Łataj teraz

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.

9.8 CVSS
0.8% EPSS
CVE-2023-27205 🔴 Łataj teraz

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.

9.8 CVSS
0.8% EPSS
CVE-2026-51366 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter

9.9 CVSS
0.3% EPSS
sql-injection 2026-08-19
CVE-2024-38889 🟠 Łataj w tym tygodniu

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used …

9.8 CVSS
0.8% EPSS
CVE-2026-3843 🟠 Łataj w tym tygodniu

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST reques…

9.8 CVSS
0.8% EPSS
CVE-2025-57631 🔴 Łataj teraz

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

9.8 CVSS
0.8% EPSS
CVE-2022-38619 🔴 Łataj teraz

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.

9.8 CVSS
0.8% EPSS
CVE-2026-50747 🟠 Łataj w tym tygodniu

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.

9.9 CVSS
0.2% EPSS
uisql-injection 2026-07-02
CVE-2022-45206 🔴 Łataj teraz

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.

9.8 CVSS
0.7% EPSS
CVE-2022-42120 🟠 Łataj w tym tygodniu

A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a Portle…

9.8 CVSS
0.7% EPSS
CVE-2026-52785 🟠 Łataj w tym tygodniu

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work…

9.9 CVSS
0.2% EPSS
sql-injection 2026-06-26
CVE-2017-5575 🟠 Łataj w tym tygodniu

SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter.

9.8 CVSS
0.7% EPSS
CVE-2023-36529 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress…

9.9 CVSS
0.2% EPSS
CVE-2022-42122 🟠 Łataj w tym tygodniu

A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the…

9.8 CVSS
0.7% EPSS
CVE-2024-35584 🟠 Łataj w tym tygodniu

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for…

8.8 CVSS
5.7% EPSS
CVE-2026-67689 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

9.8 CVSS
0.7% EPSS
sql-injection 2026-08-06
CVE-2006-5603 🔴 Łataj teraz

SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details ar…

9.8 CVSS
0.7% EPSS
CVE-2026-46624 🔴 Łataj teraz

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a …

9.9 CVSS
0.2% EPSS
CVE-2017-5879 🟠 Łataj w tym tygodniu

An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, …

9.8 CVSS
0.6% EPSS
CVE-2022-50589 🟠 Łataj w tym tygodniu

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to u…

9.8 CVSS
0.6% EPSS
CVE-2023-27667 🟠 Łataj w tym tygodniu

Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.

CVE-2023-30242 🟠 Łataj w tym tygodniu

NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.

9.8 CVSS
0.6% EPSS
CVE-2023-36361 🟠 Łataj w tym tygodniu

Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

9.8 CVSS
0.6% EPSS
CVE-2023-1863 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection.This issue affects Water Metering So…

9.8 CVSS
0.6% EPSS
eskomsql-injection 2023-04-14
CVE-2023-37847 🟠 Łataj w tym tygodniu

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

9.8 CVSS
0.6% EPSS
CVE-2022-46501 🟠 Łataj w tym tygodniu

Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.

9.8 CVSS
0.6% EPSS
CVE-2024-53480 🔴 Łataj teraz

Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.

9.8 CVSS
0.6% EPSS
CVE-2026-57517 🟠 Łataj w tym tygodniu

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST para…

9.8 CVSS
0.6% EPSS
rcesql-injection 2026-07-01
CVE-2024-8950 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection. This issue affects Piramit Automation: before 27.09.2…

9.9 CVSS
0.1% EPSS
sql-injection 2024-12-25
CVE-2023-51927 🟠 Łataj w tym tygodniu

YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.

9.8 CVSS
0.5% EPSS
yonyousql-injection 2024-01-20
CVE-2021-27130 🔴 Łataj teraz

Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.

9.8 CVSS
0.5% EPSS
CVE-2024-29667 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter.

9.8 CVSS
0.5% EPSS
sql-injection 2024-03-29
CVE-2024-51064 🔴 Łataj teraz

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.

9.8 CVSS
0.5% EPSS
CVE-2026-52186 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc component

9.8 CVSS
0.5% EPSS
sql-injection 2026-07-01
CVE-2026-51821 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint

9.8 CVSS
0.5% EPSS
sql-injection 2026-07-13
CVE-2023-37647 🟠 Łataj w tym tygodniu

SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.

9.8 CVSS
0.5% EPSS
CVE-2023-39807 🟠 Łataj w tym tygodniu

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.

9.8 CVSS
0.5% EPSS
nvkisql-injection 2023-08-21
CVE-2024-2804 🟠 Łataj w tym tygodniu

The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to insufficient escaping on the user supplied parameter and lack of su…

9.8 CVSS
0.5% EPSS
sql-injection 2024-04-09
CVE-2023-1091 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects…

9.8 CVSS
0.5% EPSS
CVE-2026-34400 🟠 Łataj w tym tygodniu

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms d…

9.8 CVSS
0.5% EPSS
CVE-2023-39805 🟠 Łataj w tym tygodniu

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.

9.8 CVSS
0.5% EPSS
CVE-2023-39806 🟠 Łataj w tym tygodniu

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.

9.8 CVSS
0.5% EPSS
CVE-2023-38954 🟠 Łataj w tym tygodniu

ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.

9.8 CVSS
0.5% EPSS
zktecosql-injection 2023-08-03
CVE-2023-45379 🟠 Łataj w tym tygodniu

In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection.

9.8 CVSS
0.5% EPSS
CVE-2024-51065 🔴 Łataj teraz

Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

9.8 CVSS
0.5% EPSS
CVE-2024-50942 🟠 Łataj w tym tygodniu

qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.

9.8 CVSS
0.5% EPSS
sql-injection 2024-11-26
CVE-2026-57308 🟠 Łataj w tym tygodniu
apps

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked querie…

9.8 CVSS
0.5% EPSS
apachesql-injection 2026-07-20
CVE-2023-2449 🟠 Łataj w tym tygodniu

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on …

9.8 CVSS
0.5% EPSS
CVE-2023-1153 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.…

9.8 CVSS
0.5% EPSS
CVE-2026-17543 🟠 Łataj w tym tygodniu
dev

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8…

9.8 CVSS
0.5% EPSS
phpsql-injection 2026-07-30
CVE-2026-34099 🟠 Łataj w tym tygodniu

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required. An unauthenticated …

9.8 CVSS
0.5% EPSS
sql-injection 2026-07-01
CVE-2026-65321 🟠 Łataj w tym tygodniu

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELE…

9.8 CVSS
0.5% EPSS
sql-injection 2026-08-02
CVE-2026-32227 🟠 Łataj w tym tygodniu
apps

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue.

9.8 CVSS
0.5% EPSS
apachesql-injection 2026-08-10
CVE-2026-25544 🟠 Łataj w tym tygodniu

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attac…

9.8 CVSS
0.4% EPSS
CVE-2025-14179 🟠 Łataj w tym tygodniu
dev

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construc…

9.8 CVSS
0.4% EPSS
phpsql-injection 2026-05-10
CVE-2026-54419 🟠 Łataj w tym tygodniu

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. The applica…

9.8 CVSS
0.4% EPSS
sql-injection 2026-06-18
CVE-2026-9711 🟠 Łataj w tym tygodniu

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping …

9.8 CVSS
0.4% EPSS
sql-injection 2026-06-30
CVE-2026-5955 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.

9.8 CVSS
0.4% EPSS
sql-injection 2026-07-09
CVE-2026-34220 🟠 Łataj w tym tygodniu

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpr…

9.8 CVSS
0.4% EPSS
CVE-2022-3792 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating syst…

9.8 CVSS
0.4% EPSS
CVE-2026-45779 🟠 Łataj w tym tygodniu

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute arbitrary SQ…

9.8 CVSS
0.4% EPSS
CVE-2026-41460 🔴 Łataj teraz

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated…

9.8 CVSS
0.4% EPSS
CVE-2026-5076 🟠 Łataj w tym tygodniu

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_…

9.8 CVSS
0.4% EPSS
sql-injection 2026-06-02
CVE-2024-35563 🟠 Łataj w tym tygodniu

CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId parameter in CDGTempPermissions.

9.8 CVSS
0.4% EPSS
sql-injection 2024-05-28
CVE-2026-25241 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows remote attackers to execute arbitrary SQL…

9.8 CVSS
0.4% EPSS
pearsql-injection 2026-02-03
CVE-2026-5801 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line Execution through SQL Injection. Th…

9.8 CVSS
0.4% EPSS
sql-injection 2026-07-10
CVE-2025-56385 🟠 Łataj w tym tygodniu

A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before…

9.8 CVSS
0.4% EPSS
CVE-2026-45288 🟠 Łataj w tym tygodniu

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without paramet…

9.8 CVSS
0.4% EPSS
sql-injection 2026-05-28
CVE-2026-48114 🟠 Łataj w tym tygodniu

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. HarvesterRegist…

9.8 CVSS
0.4% EPSS
sql-injection 2026-06-15
CVE-2026-39893 🟠 Łataj w tym tygodniu

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not require …

9.8 CVSS
0.4% EPSS
cactisql-injection 2026-06-24
CVE-2026-35184 🔴 Łataj teraz

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.

9.8 CVSS
0.4% EPSS
CVE-2026-33088 🟠 Łataj w tym tygodniu

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.

9.8 CVSS
0.4% EPSS
CVE-2026-13766 🟠 Łataj w tym tygodniu

DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor but never quote_char, so SQL::Abstra…

9.8 CVSS
0.4% EPSS
sql-injection 2026-06-30
CVE-2026-2395 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform:…

9.8 CVSS
0.4% EPSS
sql-injection 2026-07-22
CVE-2025-9953 🟠 Łataj w tym tygodniu

Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation So…

9.8 CVSS
0.3% EPSS
sql-injection 2026-02-19
CVE-2026-38158 🟠 Łataj w tym tygodniu

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.

9.8 CVSS
0.3% EPSS
sql-injection 2026-07-16
CVE-2025-4784 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection. This issue affects Tourtella: before 26.05.2025.

9.8 CVSS
0.3% EPSS
CVE-2026-25993 🟠 Łataj w tym tygodniu

EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path values—derived from the url_key stored in the database—into SQL statements…

9.8 CVSS
0.3% EPSS
CVE-2026-39955 🟠 Łataj w tym tygodniu

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in ve…

9.8 CVSS
0.3% EPSS
cactisql-injection 2026-06-24
CVE-2026-8402 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Blind SQL Injection. This issue…

9.8 CVSS
0.3% EPSS
sql-injection 2026-06-30
CVE-2025-65336 🟠 Łataj w tym tygodniu

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

9.8 CVSS
0.3% EPSS
sql-injection 2026-07-30
CVE-2026-16019 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 befor…

9.8 CVSS
0.3% EPSS
sql-injection 2026-08-19
CVE-2024-28389 🟠 Łataj w tym tygodniu

SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail(…

9.8 CVSS
0.3% EPSS
sql-injection 2024-03-19
CVE-2023-1508 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal …

9.8 CVSS
0.3% EPSS
CVE-2022-4422 🟠 Łataj w tym tygodniu

Call Center System developed by Bulutses Information Technologies before version 3.0 has an unauthenticated Sql Injection vulnerability. This has been fixed in the version 3.0

9.8 CVSS
0.3% EPSS
CVE-2023-1873 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection.This issue affects Bircard: before 23.04.05.

9.8 CVSS
0.3% EPSS
CVE-2024-25910 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

9.8 CVSS
0.3% EPSS
CVE-2026-14363 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Exten…

9.8 CVSS
0.3% EPSS
CVE-2020-29297 🔴 Łataj teraz

Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.

9.8 CVSS
0.3% EPSS
CVE-2026-38812 🟠 Łataj w tym tygodniu

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive …

9.8 CVSS
0.3% EPSS
sql-injection 2026-06-15
CVE-2026-55740 🟠 Łataj w tym tygodniu

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is …

9.8 CVSS
0.3% EPSS
sql-injection 2026-06-18
CVE-2026-58521 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Exten…

9.8 CVSS
0.3% EPSS
CVE-2026-65890 🟠 Łataj w tym tygodniu

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

9.8 CVSS
0.3% EPSS
CVE-2023-34575 🔴 Łataj teraz

SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFront…

9.8 CVSS
0.3% EPSS
CVE-2026-25236 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been …

9.8 CVSS
0.3% EPSS
pearsql-injection 2026-02-03
CVE-2026-25238 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. Th…

9.8 CVSS
0.3% EPSS
pearsql-injection 2026-02-03
CVE-2026-25240 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are provided as an array and interpolated i…

9.8 CVSS
0.3% EPSS
pearsql-injection 2026-02-03
CVE-2026-4321 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection. This issue affects Destekz: th…

9.8 CVSS
0.3% EPSS
sql-injection 2026-07-03
CVE-2026-8307 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 08072026. NOTE: The ven…

9.8 CVSS
0.3% EPSS
sql-injection 2026-07-08
CVE-2026-2397 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072…

9.8 CVSS
0.3% EPSS
sql-injection 2026-07-10
CVE-2026-5134 🟠 Łataj w tym tygodniu

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOT…

9.8 CVSS
0.3% EPSS
sql-injection 2026-08-06
CVE-2022-29650 🟠 Łataj w tym tygodniu

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.

9.8 CVSS
0.3% EPSS