By weakness (CWE)

CWE-89: related vulnerabilities

CVEs classified under CWE-89. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

440 published vulnerabilities · page 3 of 5

  • CVE-2026-10620HIGH 7.3

    A SQL injection vulnerability exists in code-projects Student Admission System version 1.0. The flaw resides in the /index.php file and can be exploited by manipulating the eid or did parameters. An attacker can inject malicious SQL commands without authentication, potentially reading or modifying sensitive student and admission data. Public exploit code is available, increasing the likelihood of active exploitation.

  • CVE-2026-10704HIGH 7.3

    SourceCodester's Pizzafy E-Commerce System version 1.0 contains a SQL injection vulnerability in the administrative login function. An attacker can manipulate the username field during authentication to inject malicious SQL commands, potentially gaining unauthorized database access without needing credentials or user interaction. The vulnerability is network-accessible and exploits are now publicly available.

  • CVE-2026-10877HIGH 7.3

    A SQL injection vulnerability exists in the SourceCodester Ship Ferry Ticket Reservation System version 1.0 and earlier. An attacker can exploit the admin login page by manipulating the Username parameter to execute arbitrary SQL commands remotely. No authentication is required to attempt the attack, and the vulnerability has already been publicly disclosed with functional exploits available.

  • CVE-2026-11334HIGH 7.3

    A SQL injection vulnerability exists in tittuvarghese CollegeManagementSystem that allows unauthenticated attackers to manipulate the department_code parameter in the dashboard form submission handler, leading to unauthorized database access and potential data theft or modification. The vulnerability is remotely exploitable without authentication, and public exploit information is already available. The affected software uses continuous delivery with rolling releases, making version tracking impractical.

  • CVE-2026-11342HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation System version 1.0. An attacker can manipulate the 'room' parameter in the /details.php file to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the affected application.

  • CVE-2026-11435HIGH 7.3

    Jinher OA 1.0 contains a SQL injection vulnerability in its nextselectplan.aspx file. An attacker can manipulate the httpOID parameter to inject malicious SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires no authentication and can be exploited over the network. Proof-of-concept code has been publicly disclosed.

  • CVE-2026-11456HIGH 7.3

    Chanjet CRM 1.0 contains a SQL injection vulnerability in its HTTP GET request handler, specifically in the /tools/jxf_dump_systable.php file. An attacker can manipulate the gblOrgID parameter to inject malicious SQL commands, potentially allowing unauthorized access to or modification of database contents. The vulnerability requires no authentication and can be exploited over the network. Exploit code is publicly available, increasing the risk of active exploitation.

  • CVE-2026-11471HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, affecting the password input field on the /index2.php page. An attacker can send a specially crafted login request over the network to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive database records. The attack requires no authentication and can be executed remotely. Public exploit code is available, increasing the risk of opportunistic exploitation.

  • CVE-2026-11472HIGH 7.3

    SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the Password parameter of /index1.php. An unauthenticated attacker can send specially crafted requests to the application to bypass authentication, extract database contents, or modify data. The vulnerability requires no user interaction and can be exploited over the network. Public exploit code exists, elevating risk significantly.

  • CVE-2026-11482HIGH 7.3

    A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can manipulate the 'sy' parameter in the /archive5.php file to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive database records. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-11483HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can send a specially crafted request to the /archive4.php endpoint that manipulates the 'sy' parameter to inject arbitrary SQL commands. Because no authentication is required and the vulnerability can be exploited over the network, a remote attacker can exploit this flaw to read, modify, or delete database records. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-11484HIGH 7.3

    A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /archive3.php file where an attacker can manipulate the 'sy' parameter to inject malicious SQL commands. Because no authentication is required and the attack can be carried out over the network, an unauthenticated attacker can exploit this to read, modify, or delete data from the underlying database. Public proof-of-concept code is now available, increasing the likelihood of real-world attacks.

  • CVE-2026-11485HIGH 7.3

    SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /archive2.php file. An attacker can manipulate the 'sy' parameter to inject malicious SQL commands, potentially compromising data confidentiality, integrity, and availability. The vulnerability requires no authentication and can be exploited remotely over the network. Public disclosure has occurred, increasing the likelihood of active exploitation.

  • CVE-2026-11486HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. The flaw is located in the /archive1.php file, where user input in the 'sy' parameter is not properly sanitized before being used in database queries. An attacker can exploit this remotely without authentication to read, modify, or delete database contents. Public exploit code is available, increasing the practical risk.

  • CVE-2026-11488HIGH 7.3

    A SQL injection vulnerability exists in Simple Flight Ticket Booking System version 1.0. The flaw resides in the checkUser.php file where user input in the Username parameter is not properly sanitized before being used in database queries. An attacker can exploit this remotely without authentication by submitting malicious SQL code through the POST request, potentially reading, modifying, or deleting database contents. Public disclosure of this vulnerability means active exploitation is a realistic concern.

  • CVE-2026-11489HIGH 7.3

    A SQL injection vulnerability exists in the Online Music Site application version 1.0, specifically in the album deletion administrative function. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially compromising the database. The vulnerability requires no authentication and can be exploited remotely, making it a significant risk for any instance of this application exposed to untrusted networks.

  • CVE-2026-11490HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Music Site version 1.0. The flaw is in the Search.php file where the Category parameter is not properly validated before being used in database queries. An attacker can send a specially crafted request over the network to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. The vulnerability requires no authentication and no user interaction, making it accessible to anyone on the internet. Public exploit code is available.

  • CVE-2026-11501HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System version 1.0. An attacker can manipulate the ID parameter in the patient-saving function to inject malicious SQL commands, potentially reading, modifying, or deleting patient records without authentication. The vulnerability is network-accessible and exploit code is publicly available, raising the risk of immediate abuse.

  • CVE-2026-11530HIGH 7.3

    A SQL injection vulnerability exists in the imvks786 student management system's login component. An attacker can manipulate the username and password parameters to inject malicious SQL commands, potentially gaining unauthorized access to the system or extracting sensitive student data. The vulnerability is remotely exploitable without authentication and does not require user interaction, making it a straightforward attack vector. Public exploit code is available, elevating the risk of active exploitation.

  • CVE-2026-11531HIGH 7.3

    A SQL injection vulnerability exists in the imvks786 student management system's administrator login endpoint. An attacker can manipulate username and password parameters to inject malicious SQL commands, potentially gaining unauthorized access or extracting sensitive data. The flaw affects the admin/admin_login.php file and can be exploited remotely without authentication. Public exploit code is available, increasing active threat likelihood.

  • CVE-2026-11582HIGH 7.3

    CodeAstro Student Attendance Management System version 1.0 contains a SQL injection vulnerability in its web-based attendance interface. An attacker can manipulate the Username parameter in the /attendance-php/index.php file to inject malicious SQL commands, potentially allowing unauthorized access to student records, attendance data, or other sensitive information stored in the application's database. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the application.

  • CVE-2026-12775HIGH 7.3

    A SQL injection vulnerability exists in Montodel House-Rental-Management's login page. An attacker can manipulate the Username parameter in /login.php to inject malicious SQL commands, potentially reading, modifying, or deleting database contents without authentication. The vulnerability is remotely exploitable and requires no user interaction—an attacker can trigger it directly by sending a crafted request. Exploit code is publicly available, increasing the risk of active attacks.

  • CVE-2026-13485HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, accessible through the /preview.php file. An attacker can manipulate the course_year_section parameter to inject malicious SQL commands, potentially allowing unauthorized data access, modification, or deletion. The vulnerability requires no authentication or user interaction and can be exploited over the network. Public exploit information is available, increasing the practical risk.

  • CVE-2026-13486HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, specifically in the /preview6.php file. An attacker can manipulate the 'course_year_section' parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited from the internet. Public exploit code has been released, increasing the practical risk.

  • CVE-2026-13487HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can exploit a parameter in the /archive.php file to execute arbitrary SQL commands against the application's database. The vulnerability requires no authentication and can be triggered over the network, making it accessible to remote attackers. Exploit code is already publicly available, increasing the risk of active exploitation.

  • CVE-2026-13488HIGH 7.3

    A SQL injection vulnerability has been discovered in SourceCodester's Class and Exam Timetabling System version 1.0. The flaw exists in the /preview7.php file and can be exploited by manipulating the 'course_year_section' parameter. An attacker can send a specially crafted request over the internet to execute arbitrary SQL commands against the underlying database, potentially reading, modifying, or deleting sensitive data. The vulnerability requires no authentication or user interaction, and exploit code has already been released publicly, making active exploitation a genuine risk.

  • CVE-2026-13498HIGH 7.3

    A SQL injection vulnerability exists in the yashpokharna2555 restaurant management system, specifically in the password recovery feature. An attacker can manipulate the email parameter in POST requests to /forgotpassword.php to inject malicious SQL commands. Because the application fails to sanitize user input, an unauthenticated attacker on the internet can execute this attack without special privileges or user interaction, potentially gaining unauthorized access to sensitive database records.

  • CVE-2026-13521HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester's Class and Exam Timetabling System version 1.0, specifically in the /preview5.php file. An attacker can manipulate the 'course_year_section' parameter to inject malicious SQL commands without needing authentication. The vulnerability allows remote exploitation and poses a meaningful risk to confidentiality, integrity, and availability of affected systems. Exploit code is already publicly available.

  • CVE-2026-13526HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0. An attacker can inject malicious SQL commands through the ID parameter in the /edit_class.php file, allowing remote exploitation without authentication. This flaw enables attackers to read, modify, or delete database records. Public exploits are available, increasing the likelihood of active attacks.

  • CVE-2026-13527HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 that allows unauthenticated attackers to manipulate database queries through the course_year_section parameter in the /preview4.php file. The vulnerability can be exploited remotely without user interaction, potentially allowing attackers to read, modify, or delete sensitive academic data. Public disclosure of this vulnerability means that attack code is already available, increasing the risk of active exploitation.

  • CVE-2026-13550HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Baptism Information Management System version 1.0. An attacker can send a specially crafted request to the /delbaptism.php file that manipulates the ID parameter to inject malicious SQL commands. This could allow unauthorized access to, modification of, or deletion of data in the underlying database. The vulnerability requires no authentication and can be exploited from the internet by an unauthenticated attacker. Public exploit code has been released, increasing the risk of active attacks.

  • CVE-2026-13551HIGH 7.3

    itsourcecode's Baptism Information Management System version 1.0 contains a SQL injection vulnerability in its editBaptism.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data. The vulnerability requires no authentication and can be exploited remotely, making it a practical concern for organizations running this software. Public exploit disclosure means this risk is elevated in the current threat landscape.

  • CVE-2026-13552HIGH 7.3

    A SQL injection vulnerability exists in itsourcecode Online Hotel Management System version 1.0 that allows unauthenticated remote attackers to manipulate database queries through the amenities management interface. By tampering with the amen_id parameter in the admin panel, an attacker can execute arbitrary SQL commands without requiring valid credentials or user interaction. The vulnerability has been publicly disclosed and exploit code is available, increasing the practical risk.

  • CVE-2026-13555HIGH 7.3

    itsourcecode Online Hotel Management System version 1.0 contains a SQL injection vulnerability in its admin user management interface. An unauthenticated attacker can send a crafted request to the /admin/mod_users/controller.php endpoint with malicious input in the Name parameter, allowing them to execute arbitrary SQL queries against the backend database. This could lead to unauthorized data access, modification, or deletion. Public exploit code exists for this vulnerability, increasing the immediate risk.

  • CVE-2026-13559HIGH 7.3

    A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the single-list_sale.php file. An unauthenticated attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to, modification of, or deletion of database records. The vulnerability is remotely exploitable and public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-13565HIGH 7.3

    SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_class1.php endpoint. An unauthenticated attacker can manipulate the ID parameter to inject arbitrary SQL commands, potentially reading, modifying, or deleting database records. The vulnerability is remotely exploitable without authentication and has been publicly disclosed, meaning attack code may be in active circulation.

  • CVE-2026-13566HIGH 7.3

    A SQL injection vulnerability has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /preview3.php file, where user-supplied input in the course_year_section parameter is not properly sanitized before being used in database queries. An attacker can send a specially crafted request to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive academic data. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14640HIGH 7.3

    CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its login functionality. An attacker can manipulate the Username parameter on the /index.php login page to inject malicious SQL commands, bypassing authentication and potentially accessing sensitive data. The vulnerability requires no authentication or user interaction to exploit and can be executed remotely over the network. Public exploit code is available, increasing the immediate risk to deployed systems.

  • CVE-2026-14641HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, accessible through the /edit_course.php endpoint. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially extracting, modifying, or deleting database records. No authentication is required, and the vulnerability can be exploited over the network. Public disclosure means threat actors have ready-made exploitation techniques available.

  • CVE-2026-14642HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 in the /edit_class2.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially allowing unauthorized access to or modification of the database. The vulnerability requires no authentication and can be exploited remotely. Public exploit code is available, increasing the risk of active exploitation.

  • CVE-2026-14648HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Voting System affecting versions up to 0.x/1.0. The flaw resides in the login authentication component, specifically in how the system processes the adminUserName and adminPassword parameters. An attacker can bypass authentication and manipulate the underlying database by injecting malicious SQL commands through these input fields. Because the vulnerability allows unauthenticated remote exploitation and the exploit code is publicly available, it poses an immediate threat to any organization running this voting system.

  • CVE-2026-14649HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Voting System version 1.0. The vulnerability affects the voting submission functionality, specifically the `/saveVote.php` file's `test_input` function. An attacker can manipulate voter-related fields (voterName, voterEmail, voterID, or selectedCandidate) to inject malicious SQL commands. Because the vulnerability requires no authentication and can be triggered remotely over the network, an attacker can exploit it without prior system access or user interaction.

  • CVE-2026-14652HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the username field on the admin login page. This could enable attackers to bypass authentication, extract sensitive data, modify database contents, or cause system disruption. The vulnerability is network-accessible and requires no user interaction or authentication to exploit, making it immediately actionable for threat actors. Public exploit information is available, increasing real-world attack probability.

  • CVE-2026-14653HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. The vulnerability is located in the admin panel at /admin/mensproductdeletequery.php and can be exploited by manipulating the user_id parameter. An attacker can send a specially crafted request over the network without authentication to inject malicious SQL commands, potentially reading, modifying, or deleting database contents. Public exploit code is available, elevating the immediate risk.

  • CVE-2026-14654HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. An attacker can manipulate the user_id parameter in the /admin/girlsproductdeletequery.php file to inject malicious SQL commands. Because this admin endpoint requires no authentication and can be accessed over the network, an unauthenticated remote attacker can exploit this flaw to read, modify, or delete database contents. Public exploits are already available, increasing the practical risk.

  • CVE-2026-14660HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Job Portal version 1.0 that allows unauthenticated attackers to manipulate login credentials and execute arbitrary SQL queries. The vulnerability is in the login.php file, specifically in how it processes the txtUser and txtPass parameters. An attacker can craft malicious input to bypass authentication, extract sensitive data, or modify the database. Public exploit information is available, increasing the risk of active exploitation.

  • CVE-2026-14688HIGH 7.3

    itsourcecode Online Hotel Management System version 1.0 contains a SQL injection vulnerability in its admin login functionality. An attacker can exploit a flaw in how the system processes the email parameter to inject malicious SQL commands without authentication, potentially exposing or modifying sensitive data in the underlying database. The vulnerability is network-accessible and proof-of-concept exploits are publicly available.

  • CVE-2026-14695HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Multi-Vendor Online Grocery Management System version 1.0, specifically in the user registration function. An attacker can send a malicious request with a specially crafted name field to bypass input validation and execute arbitrary SQL commands against the backend database. No authentication is required, and the vulnerability can be exploited over the network. Public proof-of-concept code has been released, making this an active threat.

  • CVE-2026-14700HIGH 7.3

    A SQL injection vulnerability exists in the Employer Login Endpoint of code-projects Internship Management System version 1.0. An attacker can inject malicious SQL commands through the email or password login fields without authentication, potentially accessing, modifying, or deleting sensitive data in the application's database. The vulnerability is accessible over the network and has been publicly disclosed, making active exploitation more likely.

  • CVE-2026-14705HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Examination version 1.0 that allows unauthenticated attackers to manipulate user credentials (uname/password parameters) passed to the head.php file, potentially extracting sensitive data, modifying records, or disrupting service availability. The vulnerability is network-accessible, requires no user interaction, and has been publicly disclosed with exploitation details available.

  • CVE-2026-14713HIGH 7.3

    SourceCodester Pizzafy E-Commerce System version 1.0 contains a SQL injection vulnerability in its admin panel. An attacker can manipulate the ID parameter in the /admin/ajax.php?action=confirm_order endpoint to execute arbitrary SQL commands without authentication. Because the vulnerability is remotely exploitable and requires no user interaction, it poses a significant risk to affected systems. Public exploit code is available, increasing the likelihood of active attacks.

  • CVE-2026-14732HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 affecting the /edit_exam.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires no authentication and can be exploited over the network. Public exploit code is available, increasing the practical risk.

  • CVE-2026-14733HIGH 7.3

    SourceCodester Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_coursea.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, potentially gaining unauthorized access to or modifying the underlying database. This vulnerability requires no authentication and can be exploited remotely over the network. Public exploits are currently available.

  • CVE-2026-14734HIGH 7.3

    A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /edit_product.php file where user-supplied input in the ID parameter is not properly validated before being used in database queries. An attacker can exploit this remotely without authentication to execute arbitrary SQL commands, potentially reading, modifying, or deleting sensitive data. Public exploit code is available, elevating the practical risk.

  • CVE-2026-14735HIGH 7.3

    A SQL injection vulnerability exists in code-projects Smart Parking System version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the street, city, or status parameters in the /parkings/parkings.php file. An attacker can exploit this remotely without any user interaction to read, modify, or delete database contents. The vulnerability has been publicly disclosed, increasing the immediate risk of active exploitation.

  • CVE-2026-14737HIGH 7.3

    A SQL injection flaw exists in Hanwang e-Face General Management Platform version 6.3.5.4 affecting the /sysAuthStr/querySysAuthStr.do endpoint. By manipulating the order of function arguments, an attacker can inject malicious SQL commands without authentication. The vulnerability can be exploited remotely and proof-of-concept code is publicly available, raising the risk of active exploitation.

  • CVE-2026-14743HIGH 7.3

    A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the /normalHomeSale.php file. An attacker can manipulate the 'loc' parameter to inject malicious SQL commands, potentially gaining unauthorized access to the database. The vulnerability requires no authentication and can be exploited remotely by anyone with network access to the affected application. A public exploit is already available, increasing the practical risk.

  • CVE-2026-14744HIGH 7.3

    A SQL injection vulnerability exists in Real State Services version 1.0, specifically in the /normalHomeRental.php file. The flaw allows attackers to manipulate the 'loc' parameter to execute arbitrary SQL commands against the application's database. Since this vulnerability can be triggered remotely without authentication, and exploit code has been publicly released, organizations using this software face active exploitation risk.

  • CVE-2026-14745HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows unauthenticated attackers to manipulate the ID parameter in the /single-list_rent.php file, potentially exposing or altering sensitive data in the underlying database. The vulnerability can be exploited remotely without authentication, and proof-of-concept code is publicly available, increasing the risk of active exploitation.

  • CVE-2026-14746HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows unauthenticated remote attackers to manipulate the 'amen' parameter in the /addprojectrent.php file to execute arbitrary SQL queries. The vulnerability has been publicly disclosed and exploitation code is available, increasing the risk of active exploitation. Any organization running this real estate management application should treat this as a high-priority security issue requiring immediate patching or mitigation.

  • CVE-2026-14747HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 that allows an unauthenticated attacker to inject malicious SQL commands through the 'amen' parameter in the /addprojectsale.php file. Because no authentication is required and the vulnerability can be exploited over the network, an attacker could potentially read, modify, or delete database records without legitimate access. This is a remotely exploitable flaw affecting a real estate management application.

  • CVE-2026-14750HIGH 7.3

    A SQL injection vulnerability has been identified in mjperpinosa stumasy, a project using continuous rolling releases. An attacker can manipulate the Password parameter in the Notes controller's dictionary authorization function to inject malicious SQL commands, potentially compromising database integrity and extracting sensitive information. The flaw is remotely exploitable without requiring authentication, and proof-of-concept code has already been released publicly, increasing the risk of active exploitation.

  • CVE-2026-14754HIGH 7.3

    A SQL injection vulnerability exists in Hotel and Tourism Reservation version 1.0, specifically in the admin room management interface. An unauthenticated attacker can manipulate several input parameters—including room description, price, type, number, and image deletion fields—to execute arbitrary SQL commands against the backend database. The vulnerability requires no user interaction and can be exploited remotely, making it a direct network-based attack surface.

  • CVE-2026-14755HIGH 7.3

    A SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation system version 1.0. The flaw is located in the reservations management page at /admin/reservations.php, where user input passed through the 'delete' parameter is not properly validated before being used in database queries. An unauthenticated attacker on the network can exploit this remotely to read, modify, or delete sensitive reservation data and potentially gain deeper access to the system. Public disclosure means defensive awareness is urgent.

  • CVE-2026-14756HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation system (version 1.0) that allows unauthenticated attackers to manipulate database queries through the tour deletion function. An attacker can send a specially crafted request to the `/admin/add_tour.php` page targeting the `delete_image` parameter to execute arbitrary SQL commands, potentially accessing, modifying, or deleting sensitive reservation and customer data. The vulnerability requires no special privileges or user interaction, making it straightforward to exploit over the network. Public exploit information is already available, elevating the urgency of patching.

  • CVE-2026-14762HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation system version 1.0, specifically in the room management administrative interface. An attacker can manipulate the 'delete' parameter in the /admin/rooms.php file to execute unauthorized database queries without authentication. This allows remote attackers to read, modify, or delete sensitive data from the reservation system's database. The vulnerability is now public and active exploits are known to exist.

  • CVE-2026-14763HIGH 7.3

    A SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation version 1.0 that allows unauthenticated attackers to inject malicious SQL commands through the tour parameter in the administrative tour reservations page. An attacker can exploit this remotely without special privileges or user interaction, potentially compromising sensitive reservation and customer data stored in the application database.

  • CVE-2026-14764HIGH 7.3

    A SQL injection vulnerability exists in the Hotel and Tourism Reservation system version 1.0, specifically in the event management administrative interface. An attacker can inject malicious SQL commands through the event details parameter to manipulate database queries without requiring authentication. This allows unauthorized access to, modification of, or deletion of sensitive data stored in the application database.

  • CVE-2026-14768HIGH 7.3

    A SQL injection vulnerability has been discovered in code-projects Real State Services version 1.0 affecting the /builderHome.php file. An attacker can inject malicious SQL commands through the 'loc' parameter without authentication, potentially reading, modifying, or deleting database records. Public exploit code is available, making this a practical threat that requires immediate patching.

  • CVE-2026-14769HIGH 7.3

    A SQL injection vulnerability exists in code-projects Real State Services version 1.0 affecting the /pay.php file. An unauthenticated attacker can inject malicious SQL code through the Bankname parameter to manipulate database queries, potentially reading, modifying, or deleting sensitive data. The vulnerability is remotely exploitable without any user interaction, and proof-of-concept code has been publicly disclosed, increasing immediate risk.

  • CVE-2026-14770HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 that allows unauthenticated remote attackers to manipulate the ID parameter in the /edit_room.php file to execute arbitrary database queries. The vulnerability requires no user interaction and can be exploited from the network without authentication, making it a significant remote code execution risk for organizations running this scheduling software.

  • CVE-2026-14771HIGH 7.3

    SourceCodester's Class and Exam Timetabling System version 1.0 contains a SQL injection vulnerability in the /edit_exam1.php file. An attacker can manipulate the ID parameter to inject malicious SQL commands, allowing them to read, modify, or delete database contents without authentication. Because this vulnerability requires no user interaction and can be exploited over the network, it represents a significant risk to organizations running this application.

  • CVE-2026-14772HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0 affecting the /edit_course1.php file. An attacker can manipulate the ID parameter to inject arbitrary SQL commands, potentially reading, modifying, or deleting database records. The vulnerability requires no authentication and can be exploited over the network. Public disclosure has occurred, increasing exploitation risk.

  • CVE-2026-15134HIGH 7.3

    CodeAstro Simple Online Leave Management System version 1.0 contains a SQL injection vulnerability in its index.php file. An attacker can manipulate the email parameter to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data without authentication. The vulnerability is network-accessible and exploit code has already been made public, increasing the risk of active exploitation.

  • CVE-2026-15135HIGH 7.3

    A SQL injection vulnerability exists in code-projects Online Food Order System version 1.0, specifically in the /edit_food_items.php file. An attacker can manipulate the 'update' parameter to inject arbitrary SQL commands without authentication. This allows remote code execution and data manipulation. Public exploits are available, increasing immediate risk.

  • CVE-2026-15137HIGH 7.3

    A SQL injection vulnerability has been discovered in code-projects Interview Management System version 1.0. An attacker can manipulate the ID parameter in the application to inject malicious SQL commands, potentially reading, modifying, or deleting sensitive data in the backend database. The vulnerability requires no authentication and can be triggered from the network without user interaction. Public exploit code is available, elevating the risk of active exploitation.

  • CVE-2026-15190HIGH 7.3

    A SQL injection vulnerability exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0. An attacker can manipulate the Username parameter in the login page (/login.php) to inject malicious SQL commands, potentially accessing, modifying, or deleting sensitive data without authentication. The vulnerability is network-accessible and requires no user interaction, making it straightforward to exploit. Public exploit code is now available.

  • CVE-2026-40083HIGH 7.2

    Cacti, a widely-deployed open source framework for performance monitoring and fault management, contains a SQL injection flaw in its SNMP agent management feature. An authenticated attacker with SNMP manager permissions can manipulate serialized data in a request parameter to inject arbitrary SQL commands into the database. The vulnerability stems from unsafe deserialization followed by direct concatenation of unsanitized values into a DELETE query. Cacti versions 1.2.30 and earlier are affected; the fix is available in version 1.2.31.

  • CVE-2016-20063HIGH 7.1

    Single Personal Message version 1.0.3 contains a SQL injection flaw that allows authenticated users to inject malicious database commands through the message parameter. An attacker with user credentials can craft specially-designed messages to execute arbitrary SQL queries, potentially extracting sensitive data such as user credentials and site configuration details from the underlying database.

  • CVE-2017-20264HIGH 7.1

    Joomla! Component Sponsor Wall version 8.0 contains a critical weakness that allows attackers to inject malicious SQL commands without logging in. By crafting a specially designed web request, an attacker can trick the component into executing unauthorized database queries, potentially exposing usernames, passwords, and other sensitive configuration data. The vulnerability requires user interaction (clicking a malicious link), but no authentication is needed to attempt the attack.

  • CVE-2017-20265HIGH 7.1

    A SQL injection flaw in Joomla! Component Flip Wall version 8.0 allows unauthenticated attackers to inject malicious database commands through a web parameter. By crafting a specially formatted web request, an attacker can query the underlying database directly—potentially exposing user credentials, configuration data, or other sensitive information. The attack requires no authentication and can be triggered simply by clicking a malicious link or visiting a compromised page.

  • CVE-2018-25392HIGH 7.1

    MaxOn ERP Software versions 8.x through 9.x contain a SQL injection flaw that lets authenticated users inject malicious SQL commands through specific parameters in the activity logging function. An attacker with valid credentials can craft POST requests to extract sensitive database information such as version numbers and database names. While exploitation requires authentication, the impact—unauthorized access to database structure and sensitive data—represents a meaningful security risk for organizations running these versions.

  • CVE-2018-25410HIGH 7.1

    SIM-PKH version 2.4.1 contains a SQL injection flaw in its admin media management interface. An authenticated attacker can craft malicious requests to the /admin/media.php endpoint that inject SQL code, allowing them to extract sensitive database information such as usernames, database names, and version details. The vulnerability requires valid login credentials but poses a meaningful risk to data confidentiality within affected deployments.

  • CVE-2018-25429HIGH 7.1

    Paroiciel version 11.20 contains an SQL injection vulnerability in the zpro.php endpoint that allows authenticated users to execute arbitrary database queries by manipulating the zProIdPro parameter. An attacker with valid credentials can craft malicious SQL statements to extract sensitive information from the database, including usernames, database names, and version details. This is a post-authentication attack that does not require user interaction.

  • CVE-2018-25430HIGH 7.1

    Paroiciel version 11.20 contains a SQL injection flaw in its egeq.php endpoint. Authenticated users can craft malicious requests that embed SQL commands into the eGeqIdEquipe parameter, allowing them to query the underlying database directly. This bypasses normal access controls and could expose sensitive information such as database version details and other stored data. The vulnerability requires valid login credentials, so it represents an insider threat or compromised-account scenario.

  • CVE-2018-25431HIGH 7.1

    No-Cms 1.0 contains a SQL injection flaw in its privilege management export feature. An authenticated user can craft a specially formatted request to extract sensitive data from the application's database by injecting malicious SQL commands into the order_by parameter. The vulnerability requires valid credentials but poses significant risk to data confidentiality.

  • CVE-2019-25746HIGH 7.1

    WordPress administrators using the Sliced Invoices plugin version 3.8.2 face a SQL injection risk. An authenticated attacker—someone with valid WordPress login credentials—can craft malicious requests to the plugin's admin interface to read or alter database contents. While this requires existing access to WordPress, the vulnerability poses meaningful risk to organizations managing invoices through this plugin, especially in multi-user environments or where account credentials may be compromised.

  • CVE-2019-25749HIGH 7.1

    Joomla J-CruisePortal version 6.0.4 is vulnerable to SQL injection through the guest_adult parameter. An authenticated attacker can craft malicious SQL code within this field and send it via POST requests to the cruises endpoint, allowing them to directly query or manipulate the application's database. This is a moderately severe risk that requires user authentication to exploit but can lead to exposure of sensitive customer and operational data.

  • CVE-2019-25757HIGH 7.1

    Joomla vWishlist version 1.0.1 contains a SQL injection flaw that allows authenticated users to run arbitrary database commands. An attacker with valid login credentials can craft malicious SQL code within specific request parameters to extract sensitive database information such as version numbers and database names. This vulnerability requires authentication, which limits exposure to internal or compromised accounts.

  • CVE-2019-25759HIGH 7.1

    Joomla! Component vBizz version 1.0.7 contains a SQL injection flaw in its employee management interface. An authenticated user can craft specially-formatted requests to the payid parameter that trick the application into executing unintended database commands. This allows attackers with valid login credentials to extract sensitive information from the underlying database, including version details and table names—a serious reconnaissance and data exfiltration risk for organizations running this component.

  • CVE-2019-25761HIGH 7.1

    JoomCRM version 1.1.1, a Joomla component used for customer relationship management, contains a flaw that allows logged-in users to run unauthorized database commands. An attacker with valid credentials can manipulate a specific web request parameter to inject SQL code, potentially reading sensitive data from your database such as table structures and stored information. This is a high-severity issue because it requires authentication but grants significant read access to confidential data.

  • CVE-2026-40522HIGH 7.1

    FrontAccounting versions before 2.4.20 contain a SQL injection flaw in the Bank Statement report feature. An authenticated user can craft malicious SQL code in the report parameters to bypass normal database queries and extract sensitive information such as usernames, password hashes, and email addresses from the system. The vulnerability allows this data to be embedded into PDF reports. Because the flaw requires user login credentials to exploit, it represents a risk primarily from insiders or compromised accounts rather than unauthenticated internet attacks.

  • CVE-2026-45722HIGH 7.1

    A vulnerability in Nextcloud's Tables app allows authenticated users to inject malicious SQL code through the ORDER BY clause of database queries. While this type of SQL injection is more limited than typical variants—attackers can extract only small amounts of data per request or cause database delays—it still poses a meaningful confidentiality and availability risk. The flaw affects Nextcloud Tables versions 0.9.0 through 0.9.6 and 1.0.0 through 1.0.1. Nextcloud has released patches that organizations should apply promptly.

  • CVE-2026-4776HIGH 7.1

    Mautic, a popular marketing automation platform, contains an SQL injection flaw in its API that allows authenticated users to execute unauthorized database queries. The vulnerability stems from incomplete filtering of nested query parameters in the contact filtering API—an attacker with valid API credentials can craft specially formed requests to bypass safety checks and inject SQL commands directly into database queries. This could lead to unauthorized data access or limited system disruption, though the attacker must already have valid API authentication.

  • CVE-2025-71332MEDIUM 6.5

    Flowise, a popular workflow automation platform, contains a SQL injection vulnerability in its chatflow import feature. An authenticated attacker can upload a specially crafted JSON file that executes arbitrary SQL commands on the backend database. The vulnerability stems from a failure to properly sanitize the chatflow ID before inserting it into a SQL query. While authentication is required to exploit this issue, the impact is significant: attackers can extract sensitive data from the credential table, potentially compromising stored API keys, passwords, and other authentication tokens used by the platform.

  • CVE-2026-12079MEDIUM 6.5

    The Dokan Pro WordPress plugin contains a SQL injection vulnerability in how it processes the 'orderby' parameter. An authenticated user with basic Subscriber permissions can craft requests to inject SQL commands and potentially access sensitive database information. This requires an account on the WordPress site; the vulnerability does not affect unauthenticated visitors.

  • CVE-2026-12090MEDIUM 6.5

    A SQL injection vulnerability exists in the Taskbuilder WordPress plugin (versions up to 5.0.8) that allows authenticated users with subscriber-level access to extract sensitive database information. The vulnerability is in the project filtering functionality and doesn't require additional verification tokens, meaning anyone with basic WordPress account access can exploit it without further prerequisites.

  • CVE-2026-12110MEDIUM 6.5

    A WordPress plugin called Taskbuilder, which provides project and task management features with a Kanban board, contains a SQL injection vulnerability in how it processes task search requests. The vulnerability allows authenticated users—even those with basic Subscriber account privileges—to inject malicious SQL commands to extract sensitive data from the website's database. This is particularly concerning because the vulnerable AJAX function that handles task searches doesn't verify user permissions or validate session tokens, making it accessible to any logged-in user regardless of their intended role.

  • CVE-2026-13010MEDIUM 6.5

    The JoomSport plugin for WordPress contains a SQL injection vulnerability in its shortcode functionality that allows authenticated users with contributor-level permissions or higher to extract sensitive database information. An attacker with basic WordPress posting privileges can embed a malicious shortcode in a page or post that injects SQL commands to bypass normal database queries and access unauthorized data. The vulnerability affects all versions up to 5.7.9 and requires an attacker to already have legitimate WordPress access.

  • CVE-2026-13011MEDIUM 6.5

    The WP ERP (Enterprise Resource Planning) plugin for WordPress contains a SQL injection vulnerability in its employee list functionality. An attacker with HR Manager privileges or higher can manipulate a sorting parameter to inject malicious SQL commands, potentially extracting sensitive company data from the database. While the vulnerability requires authenticated access at a specific privilege level, the ability to exfiltrate data makes it a meaningful risk for organizations running this plugin.