Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,889 CVEs tagged with CWE-894,425 Critical, 8,378 High, 6,136 Medium, 949 Low, 1 Unrated.

CVE-2026-13529

Published Jun 29, 2026

A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl c…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-13527

Published Jun 29, 2026

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /preview4.php. Such manipulation of…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13526

Published Jun 29, 2026

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_class.php. This manipulation of the argument ID ca…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13525

Published Jun 29, 2026

A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13521

Published Jun 29, 2026

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php.…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13520

Published Jun 29, 2026

A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Ha…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-49048

Published Jun 28, 2026

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13498

Published Jun 28, 2026

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter H…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-13497

Published Jun 28, 2026

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the a…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13496

Published Jun 28, 2026

A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argume…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13495

Published Jun 28, 2026

A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The manipulation of the argument logi…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13488

Published Jun 28, 2026

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file /preview7…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13487

Published Jun 28, 2026

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The manipulation of the argument…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13486

Published Jun 28, 2026

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13485

Published Jun 28, 2026

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argu…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13333

Published Jun 27, 2026

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and in…

CVSS 6.5 · Medium
evidence mentions
7
Buzz score
35.8

CVE-2026-13331

Published Jun 27, 2026

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and inclu…

CVSS 6.5 · Medium
evidence mentions
8
Buzz score
37.0

CVE-2026-54350

Published Jun 26, 2026

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Ela…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
16.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-52785

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline compariso…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-57667

Published Jun 26, 2026

Sales Representative SQL Injection in Groundhogg <= 4.5 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57663

Published Jun 26, 2026

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57662

Published Jun 26, 2026

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57653

Published Jun 26, 2026

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57644

Published Jun 26, 2026

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57643

Published Jun 26, 2026

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0
Showing 301-325 of 19,889 CVEsPage 13 of 796