Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,962 CVEs tagged with CWE-894,450 Critical, 8,406 High, 6,155 Medium, 950 Low, 1 Unrated.

CVE-2026-8339

Published Jul 29, 2026

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a s…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65890

Published Jul 29, 2026

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-33385

Published Jul 29, 2026

A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration pa…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-12895

Published Jul 29, 2026

SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` w…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11973

Published Jul 29, 2026

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient…

CVSS 4.9 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-63234

Published Jul 29, 2026

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passe…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-63233

Published Jul 29, 2026

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data pa…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-63232

Published Jul 29, 2026

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data pas…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-63231

Published Jul 29, 2026

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to re…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63230

Published Jul 29, 2026

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifia…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-15344

Published Jul 29, 2026

The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient…

CVSS 4.9 · Medium
evidence mentions
10
Buzz score
30.5

CVE-2026-54658

Published Jul 28, 2026

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes dur…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-6881

Published Jul 28, 2026

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-11391

Published Jul 28, 2026

Tanium addressed a SQL injection vulnerability in Patch.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-7769

Published Jul 28, 2026

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 th…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50736

Published Jul 28, 2026

The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the priv…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-15304

Published Jul 28, 2026

The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4. This is due to insufficient e…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-15444

Published Jul 28, 2026

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and includi…

CVSS 4.9 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-16462

Published Jul 28, 2026

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-14785

Published Jul 28, 2026

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient esca…

CVSS 7.5 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-10207

Published Jul 28, 2026

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-suppli…

CVSS 7.5 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-15267

Published Jul 28, 2026

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in versions…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-14516

Published Jul 28, 2026

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, a…

CVSS 7.5 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-13161

Published Jul 28, 2026

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions…

CVSS 7.5 · High
evidence mentions
8
Buzz score
28.5

CVE-2026-12800

Published Jul 28, 2026

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST…

CVSS 7.5 · High
evidence mentions
5
Buzz score
24.4
Showing 1-25 of 19,962 CVEsPage 1 of 799