Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,915 CVEs tagged with CWE-894,433 Critical, 8,389 High, 6,143 Medium, 949 Low, 1 Unrated.

CVE-2026-54829

Published Jun 25, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issu…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54822

Published Jun 25, 2026

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-12937

Published Jun 25, 2026

The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all…

CVSS 7.5 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-2508

Published Jun 25, 2026

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficie…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
31.1

CVE-2026-12079

Published Jun 25, 2026

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping o…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-12077

Published Jun 25, 2026

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to i…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-9786

Published Jun 25, 2026

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-9785

Published Jun 25, 2026

Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-9784

Published Jun 25, 2026

Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-9783

Published Jun 25, 2026

Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-9782

Published Jun 25, 2026

Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-9781

Published Jun 25, 2026

Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-7570

Published Jun 25, 2026

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-39951

Published Jun 25, 2026

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports fe…

CVSS 7.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-39955

Published Jun 24, 2026

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-39948

Published Jun 24, 2026

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor grv() (rather tha…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-39893

Published Jun 24, 2026

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without san…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-56351

Published Jun 24, 2026

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unesc…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-71332

Published Jun 24, 2026

Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-56052

Published Jun 24, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue…

CVSS 7.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-9179

Published Jun 24, 2026

The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including…

CVSS 7.5 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-8705

Published Jun 24, 2026

The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions up to,…

CVSS 7.5 · High
evidence mentions
7
Buzz score
32.3

CVE-2026-47384

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create permission can inject SQL into the bulk groupBy endpoint by…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47375

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed base can inject arbitrary SQL i…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-61029

Published Jun 23, 2026

An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS 7.5 · High
Showing 376-400 of 19,915 CVEsPage 16 of 797