Skip to main content

CWE archive

CWE-564 CVEs

Programmatic archive

10 CVEs tagged with CWE-5640 Critical, 4 High, 4 Medium, 2 Low, 0 Unrated.

CVE-2024-58352

Published Jul 2, 2026

Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syn…

CVSS 8.7 · High

CVE-2026-40871

Published Apr 21, 2026

mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-4594

Published Mar 23, 2026

A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy of the file erupt-data/erupt-jpa/src/main/java/xyz/erupt/jp…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-4593

Published Mar 23, 2026

A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptData…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-23959

Published Jan 22, 2026

CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions prior to 4.1.9 in the `CustomerTransformerController` with…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-67280

Published Jan 9, 2026

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users an…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-22242

Published Jan 8, 2026

CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-8052

Published Oct 20, 2025

SQL Injection vulnerability in opentext Flipper allows SQL Injection.  The vulnerability could allow a low privilege user to interact with the database in unintended ways and ext…

CVSS 1.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-48988

Published Aug 22, 2025

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes t…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0959

Published Mar 7, 2025

The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_id parameter in all versions up to, and including, 3.9.9.2 d…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1