Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,913 CVEs tagged with CWE-894,433 Critical, 8,388 High, 6,142 Medium, 949 Low, 1 Unrated.

CVE-2026-57636

Published Jun 26, 2026

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57631

Published Jun 26, 2026

Administrator SQL Injection in Popup box <= 6.0.1 versions.

CVSS 7.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57628

Published Jun 26, 2026

Administrator SQL Injection in WP All Import <= 4.0.1 versions.

CVSS 7.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-56070

Published Jun 26, 2026

Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-56068

Published Jun 26, 2026

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-56067

Published Jun 26, 2026

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-56064

Published Jun 26, 2026

Subscriber SQL Injection in Tourfic <= 2.22.5 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-56062

Published Jun 26, 2026

Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-56036

Published Jun 26, 2026

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-56034

Published Jun 26, 2026

Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54831

Published Jun 26, 2026

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54827

Published Jun 26, 2026

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54825

Published Jun 26, 2026

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54820

Published Jun 26, 2026

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-13226

Published Jun 26, 2026

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and includ…

CVSS 6.5 · Medium
evidence mentions
9
Buzz score
38.0

CVE-2026-40083

Published Jun 25, 2026

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-37149

Published Jun 25, 2026

GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php.…

CVSS 7.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-57588

Published Jun 25, 2026

A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan resu…

CVSS 1.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57587

Published Jun 25, 2026

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results…

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54849

Published Jun 25, 2026

Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54843

Published Jun 25, 2026

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54838

Published Jun 25, 2026

Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54836

Published Jun 25, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a thr…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-54829

Published Jun 25, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issu…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54822

Published Jun 25, 2026

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0
Showing 351-375 of 19,913 CVEsPage 15 of 797