By weakness (CWE)
CWE-89: related vulnerabilities
CVEs classified under CWE-89. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
249 published vulnerabilities · page 3 of 3
- CVE-2026-10286MEDIUM 6.3
CodeAstro Payroll System version 1.0 contains a SQL injection vulnerability in its employee home page functionality. An authenticated attacker can inject malicious SQL commands through the emp_id parameter, allowing them to read, modify, or delete database records. This vulnerability requires valid login credentials and is reachable over the network. Public exploit information is available, increasing the immediate risk of exploitation.
- CVE-2026-10296MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 that allows authenticated users to manipulate the Username parameter in the /ajax.php endpoint to execute arbitrary SQL queries. An attacker with valid login credentials can exploit this flaw to read, modify, or delete database contents. The vulnerability requires authentication but is otherwise straightforward to exploit and has been publicly disclosed.
- CVE-2026-10297MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 within the course management functionality. An authenticated attacker can manipulate the ID parameter in the /manage_course.php endpoint to execute arbitrary SQL queries against the underlying database. The vulnerability requires valid login credentials but can be exploited over the network without additional interaction. Exploit code is publicly available, elevating the practical risk.
- CVE-2026-10302MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 within the /manage_fee.php file. An authenticated attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. The vulnerability requires valid user credentials to exploit but can be triggered remotely over the network.
- CVE-2026-10568MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the /manage_payment.php file to execute arbitrary SQL queries against the backend database. This vulnerability requires valid login credentials to exploit, but can lead to unauthorized data access, modification, or deletion. Public exploit code is available, increasing the practical risk of exploitation.
- CVE-2026-10808MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0 that allows authenticated users to manipulate the ID parameter in the /manage_student.php file, potentially enabling unauthorized data access, modification, or deletion. The vulnerability requires valid login credentials but can be exploited remotely over the network. Public exploit code is available, elevating the risk of active attack.
- CVE-2026-10809MEDIUM 6.3
CVE-2026-10809 is a SQL injection vulnerability in itsourcecode Fees Management System version 1.0. An authenticated attacker can manipulate the ID parameter in the /manage_user.php file to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The flaw requires valid login credentials but can be exploited over the network without user interaction. Public exploit code is available, elevating the practical risk despite the medium CVSS score.
- CVE-2026-10811MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Fees Management System version 1.0. The flaw resides in the /receipt.php file, specifically in how the application processes the ef_id parameter. An authenticated attacker can manipulate this parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete database records. Public disclosure of this vulnerability means exploitation techniques are already available, elevating the practical risk.
- CVE-2026-10874MEDIUM 6.3
A SQL injection vulnerability exists in projectworlds Online Art Gallery Shop Project version 1.0 affecting the admin dashboard. An authenticated attacker can manipulate the 'social_insta' parameter in the /admin/adminHome.php file to inject malicious SQL commands. This allows unauthorized access to sensitive database information, modification of data, or potential system disruption. The vulnerability requires valid login credentials but has no other technical barriers to exploitation.
- CVE-2026-10875MEDIUM 6.3
A SQL injection vulnerability exists in projectworlds Online Art Gallery Shop Project version 1.0 that allows authenticated users to inject malicious SQL commands through the social_twitter parameter in the admin panel. An attacker with login credentials can exploit this flaw to read, modify, or delete database records. Public exploit code has been released, increasing the risk of active exploitation.
- CVE-2026-11412MEDIUM 6.3
Jinher OA C6 contains a SQL injection vulnerability in a web component that processes form identifiers. An attacker with login credentials can manipulate the queryID parameter in GetFormSyn.aspx to execute arbitrary database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is network-accessible and exploit code has been publicly released, increasing the risk of active exploitation.
- CVE-2026-11453MEDIUM 6.3
Tiobon Employee Self-Service System versions up to 7.2 contain a SQL injection flaw in the blog search functionality accessible through the login endpoint. An authenticated attacker can manipulate search keywords to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability requires valid login credentials and has been publicly disclosed, though it is not currently tracked in the CISA Known Exploited Vulnerabilities catalog. The vendor has not acknowledged or addressed this issue despite early notification.
- CVE-2026-11473MEDIUM 6.3
A SQL injection vulnerability exists in jflyfox jfinal_cms versions up to 5.1.0 that allows authenticated users to manipulate the orderBy parameter in the AdvicefeedbackController, potentially exposing or modifying database contents. The vulnerability requires valid login credentials but can be exploited over the network without user interaction once authenticated.
- CVE-2026-11475MEDIUM 6.3
A SQL injection vulnerability has been discovered in Kushan2k's student-management-system affecting the Certificate Verification Endpoint. An attacker with login credentials can manipulate the 'nic' parameter in the getStatus function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability is rated MEDIUM severity and exploits have been publicly disclosed, creating immediate risk for deployed instances.
- CVE-2026-11480MEDIUM 6.3
A SQL injection vulnerability exists in BeikeShop, an e-commerce platform by Chengdu Everbrite Network Technology, affecting versions up to 1.6.0.22. An authenticated attacker can manipulate the 'settings.value' parameter in the Admin Design Builder endpoint to inject malicious SQL commands. The vulnerability requires login credentials but carries a network-based attack vector, allowing an attacker with admin or user-level access to read, modify, or delete database contents.
- CVE-2026-11495MEDIUM 6.3
CodeAstro Ingredients Stock Management System version 1.0 contains a SQL injection vulnerability in its stock addition functionality. An authenticated attacker can manipulate the ID parameter in the /Ingredients-Stock/add_stock.php file to execute arbitrary SQL queries. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid credentials to exploit but carries moderate severity due to its potential for data theft and integrity compromise.
- CVE-2026-11506MEDIUM 6.3
CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff deletion search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_for_deletion.php file to inject malicious SQL commands. This could allow unauthorized access to sensitive database information, modification of records, or disruption of the system. The vulnerability requires an authenticated login but poses a meaningful risk in environments where user accounts are shared or weak credential hygiene exists.
- CVE-2026-11507MEDIUM 6.3
A SQL injection vulnerability exists in CodeAstro Leave Management System version 1.0 that allows authenticated users to manipulate the leave_type parameter in the admin delete function, potentially extracting or modifying database information. The flaw requires valid login credentials but no additional user interaction, and public exploit code is available.
- CVE-2026-11508MEDIUM 6.3
CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff assignment search functionality. An authenticated attacker can manipulate the Name parameter in the /admin/search_staff_to_assign_pc.php file to inject malicious SQL commands. This allows remote exploitation without user interaction and poses a direct risk to database confidentiality, integrity, and availability. Public disclosure of this vulnerability means active exploitation is possible.
- CVE-2026-11509MEDIUM 6.3
CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its staff search functionality. An authenticated user can manipulate the Name parameter in the /admin/search_staff_for_updation.php file to inject arbitrary SQL commands, potentially reading or modifying sensitive employee and leave data. The vulnerability requires valid login credentials but poses a meaningful risk to organizations using this system, as it could enable unauthorized data access or manipulation by internal actors.
- CVE-2026-11510MEDIUM 6.3
CodeAstro Leave Management System version 1.0 contains a SQL injection vulnerability in its administrative interface. An authenticated attacker can manipulate the type_of_leave parameter when submitting leave requests through /admin/add_leave.php to inject malicious SQL commands. This allows unauthorized reading, modification, or deletion of database records. The vulnerability requires valid administrative credentials to exploit, but public exploit code is now available, increasing the practical risk.
- CVE-2026-11513MEDIUM 6.3
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 within the adminaccount.php file. An authenticated attacker can manipulate the Date parameter to inject arbitrary SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires valid login credentials but can be exploited over the network. Public exploits are available.
- CVE-2026-11514MEDIUM 6.3
itsourcecode Hospital Management System version 1.0 contains a SQL injection vulnerability in the patient admission form. An authenticated attacker can manipulate the admission time parameter in the /addpatient.php file to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials but can be exploited remotely with no additional user interaction.
- CVE-2026-11529MEDIUM 6.3
A SQL injection vulnerability exists in the mysql-mcp-server component (versions up to 0.2.2) that allows authenticated users to execute arbitrary SQL commands by manipulating URI parameters. An attacker with valid credentials can read, modify, or delete database records. The vulnerability has been publicly disclosed, increasing immediate risk. Upgrading to version 0.3.0 eliminates the issue.
- CVE-2026-11558MEDIUM 6.3
CodeAstro Payroll System version 1.0 contains a SQL injection vulnerability in the /home_salary.php file. An authenticated attacker can manipulate the rate or salary_rate parameter to inject malicious SQL commands, potentially allowing them to read, modify, or delete sensitive payroll data. The vulnerability requires a valid user login but can be exploited over the network without user interaction once authenticated.
- CVE-2026-11559MEDIUM 6.3
A SQL injection vulnerability exists in CodeAstro Payroll System version 1.0 that allows authenticated users to manipulate database queries through the ID parameter in the /view_account.php file. An attacker with valid credentials can inject malicious SQL commands to access, modify, or delete sensitive payroll data. The vulnerability is network-accessible and does not require additional user interaction, though authentication is required. Public exploits are now available, increasing the risk of active exploitation.
- CVE-2026-11583MEDIUM 6.3
CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in the class creation administrative function. An authenticated attacker can manipulate the className input parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid login credentials but can be exploited over the network without additional user interaction.
- CVE-2026-11584MEDIUM 6.3
A SQL injection vulnerability exists in CodeAstro Student Attendance Management System version 1.0 that allows authenticated users to manipulate a parameter in the class editing interface and execute arbitrary database commands. An attacker with login credentials can inject malicious SQL through the ID argument to read, modify, or delete sensitive student and attendance data. The vulnerability is network-accessible and exploit code has been publicly disclosed, increasing the practical attack surface.
- CVE-2026-11585MEDIUM 6.3
CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its class management functionality. An authenticated attacker can manipulate the classId parameter in the createClassArms.php file to inject malicious SQL commands, potentially allowing unauthorized access to or modification of the database. The vulnerability requires user authentication but can be exploited remotely without user interaction.
- CVE-2026-12131MEDIUM 6.3
CodeAstro Human Resource Management System version 1.0 contains a SQL injection vulnerability in its Payroll Invoice Module. An authenticated attacker can manipulate the ID parameter in the invoice function to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires valid user credentials to exploit but has low complexity and is accessible over the network. Public exploit code now exists, elevating the practical risk.
- CVE-2026-12188MEDIUM 6.3
Grit42 Grit versions up to 0.11.0 contain a SQL injection vulnerability in the GritEntityController component. An authenticated attacker can manipulate input to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive data. The vulnerability requires valid login credentials but can be exploited over the network without user interaction. Public exploits are available.
- CVE-2026-12206MEDIUM 6.3
Grit42's Grit framework versions up to 0.11.0 contain a SQL injection flaw in the DataTableEntity component. An authenticated attacker can exploit this remotely by manipulating input to the affected function, potentially allowing unauthorized access to, modification of, or deletion of database records. Public exploits exist for this vulnerability, elevating urgency for organizations using affected versions.
- CVE-2026-0075MEDIUM 5.9
CVE-2026-0075 is a SQL injection vulnerability in Google Android's contact database access functions that allows local attackers to escalate privileges without needing special permissions or user interaction. An attacker with local access to an Android device can exploit this flaw to read, modify, or delete contact information and potentially gain elevated system privileges.
- CVE-2026-48613MEDIUM 5.9
A SQL injection flaw exists in phpBB's profile field migration process. When forums upgrade from older versions, user-supplied profile field data is not properly validated before being used in database queries. An authenticated attacker with specific interaction conditions could craft malicious input to execute arbitrary SQL commands, potentially exposing or modifying forum data. The vulnerability affects only forums that upgraded from versions before 3.3.8 but have not yet reached version 3.3.11 or later.
- CVE-2026-35069MEDIUM 5.7
Dell PowerFlex Manager versions before 5.1.0.1 contain a SQL injection flaw that allows a low-privileged attacker on the same network to inject malicious SQL commands. This could enable script injection attacks, potentially compromising data confidentiality or system integrity depending on the attacker's follow-up actions. The vulnerability requires adjacent network access and valid credentials to exploit, which limits its immediate exposure but remains a real risk in internal environments.
- CVE-2026-28576MEDIUM 5.5
A SQL injection flaw in Android's Contacts Provider allows a local attacker with basic user permissions to read sensitive contact information from the device's contacts database without needing special privileges or user interaction. The vulnerability is limited to information disclosure—attackers cannot modify or delete data, but they can extract the entire contacts database contents.
- CVE-2026-10039MEDIUM 4.9
The Frontend Admin plugin for WordPress contains a SQL injection vulnerability that allows authenticated administrators to extract sensitive data from the website's database. The flaw exists in how the plugin processes the 'order' parameter—it fails to properly escape user input before inserting it into database queries. An attacker with administrator privileges can craft a malicious request containing both 'order' and 'orderby' parameters to inject additional SQL commands and retrieve unauthorized information. This vulnerability affects all versions up to and including 3.28.28.
- CVE-2026-10736MEDIUM 4.9
The Tutor LMS plugin for WordPress, a popular learning management system, contains a SQL injection flaw in versions up to 3.9.11. An authenticated administrator can inject malicious SQL commands through the 'data' parameter to extract sensitive database information. This is not an unauthenticated attack—it requires admin-level access—which significantly limits real-world exposure in most WordPress installations.
- CVE-2026-11360MEDIUM 4.9
A SQL injection vulnerability exists in the Advanced Order Export For WooCommerce plugin affecting all versions through 4.0.10. Authenticated users with shop manager privileges or higher can inject malicious SQL commands through the 'sort_direction' parameter to extract sensitive data from the WordPress database. The vulnerability requires valid authentication and specific WordPress capabilities, limiting the attack surface to trusted internal users or compromised administrator accounts.
- CVE-2026-11776MEDIUM 4.9
The Form Maker by 10Web WordPress plugin is susceptible to SQL injection through the 'groupids' parameter. An authenticated administrator can craft malicious input to execute unauthorized database queries and extract sensitive information. The vulnerability affects all versions up to and including 1.15.43 and requires administrator-level credentials to exploit.
- CVE-2026-11777MEDIUM 4.9
The Form Maker by 10Web WordPress plugin contains a SQL injection vulnerability in its 'name' parameter that allows authenticated administrators to execute arbitrary SQL queries. An attacker with admin access could extract sensitive database information by injecting malicious SQL code into form submissions. The vulnerability affects all versions up to and including 1.15.43.
- CVE-2026-6448MEDIUM 4.9
The Quiz and Survey Master plugin for WordPress contains a SQL injection flaw in how it processes the 'order' parameter. An admin-level attacker can craft malicious requests to extract sensitive data from the WordPress database. The vulnerability is time-based and blind, meaning attackers infer results through response delays rather than direct output. If the plugin's secret key becomes public, lower-privileged users could exploit it without admin credentials.
- CVE-2026-8978MEDIUM 4.9
The OptinCraft WordPress plugin contains a SQL injection vulnerability in its 'order_by' parameter that allows authenticated administrators to extract sensitive database information. The flaw exists because user input is not properly escaped before being used in database queries. While this requires admin-level access to exploit, it represents a significant insider threat risk, especially in multi-user WordPress environments where administrative accounts may be compromised or operated by untrusted parties.
- CVE-2026-10155MEDIUM 4.7
A SQL injection vulnerability exists in Bdtask Multi-Store Inventory Management System version 1.0 within the Accounts Report Handler. An authenticated attacker can manipulate the 'dtpToDate' parameter in the accounts report search function to inject malicious SQL commands. While the vulnerability requires high privileges to exploit, successful attacks could leak sensitive financial data, modify account records, or disrupt reporting functionality. Public exploit code is available, increasing real-world risk.
- CVE-2026-10171MEDIUM 4.7
A SQL injection vulnerability exists in code-projects Online Music Site version 1.0 that allows authenticated administrators to manipulate the ID parameter in the album update functionality. An attacker with admin credentials can inject malicious SQL commands through the /Administrator/PHP/AdminUpdateAlbum.php endpoint, potentially compromising database integrity and confidentiality. The vulnerability has been publicly disclosed and exploit code is available, increasing the likelihood of active exploitation.
- CVE-2026-10237MEDIUM 4.7
A SQL injection vulnerability was identified in SourceCodester Water Billing Management System version 1.0. An authenticated administrator can manipulate the ID parameter in the user management interface to inject malicious SQL commands, potentially reading or modifying sensitive database records. The vulnerability requires administrative privileges to exploit but poses a risk to data integrity and confidentiality within billing systems. Public proof-of-concept code exists, elevating the practical risk of exploitation.
- CVE-2026-12175MEDIUM 4.7
CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its student creation interface. An authenticated administrator can exploit this flaw by manipulating the admission number field to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive student and attendance data. The vulnerability requires valid admin credentials to exploit, but the attack itself is straightforward and exploit code is publicly available.
- CVE-2026-12050MEDIUM 4.3
A SQL injection vulnerability exists in pgAdmin 4's restore point functionality. When an authenticated user interacts with the named restore point endpoint, user-supplied input is concatenated directly into an SQL query rather than being safely parameterized. This allows an attacker to inject additional SQL statements. However, the injected SQL runs under the same database role the attacker already has access to through pgAdmin's Query Tool, so the practical impact is limited to what that role can already do. The vulnerability primarily concerns the fact that SQL execution bypasses the documented interface, which could matter for deployments that restrict Query Tool access at the application layer.
- CVE-2026-35068LOW 3.5
Dell PowerFlex Manager versions before 5.1.0.1 contain a SQL injection vulnerability that allows a low-privileged attacker with network access to the same segment to query the database directly and extract sensitive information. While the attacker needs valid credentials and local network access, the flaw bypasses input validation on database commands, potentially exposing configuration data, credentials, or operational metrics stored in PowerFlex deployments.