Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,915 CVEs tagged with CWE-894,433 Critical, 8,389 High, 6,143 Medium, 949 Low, 1 Unrated.

CVE-2017-20267

Published Jun 19, 2026

Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. At…

CVSS 8.8 · High

CVE-2017-20266

Published Jun 19, 2026

Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the…

CVSS 8.8 · High

CVE-2017-20265

Published Jun 19, 2026

Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through…

CVSS 7.1 · High

CVE-2017-20264

Published Jun 19, 2026

Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throu…

CVSS 7.1 · High

CVE-2017-20263

Published Jun 19, 2026

Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious c…

CVSS 8.8 · High

CVE-2017-20262

Published Jun 19, 2026

Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through…

CVSS 8.8 · High

CVE-2017-20261

Published Jun 19, 2026

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious cod…

CVSS 8.8 · High

CVE-2017-20260

Published Jun 19, 2026

Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code thro…

CVSS 8.8 · High

CVE-2017-20259

Published Jun 19, 2026

Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id…

CVSS 8.8 · High

CVE-2017-20258

Published Jun 19, 2026

Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici…

CVSS 8.8 · High

CVE-2017-20257

Published Jun 19, 2026

Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the ajaxaction.flag_que…

CVSS 8.8 · High

CVE-2017-20256

Published Jun 19, 2026

Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through…

CVSS 8.8 · High

CVE-2017-20255

Published Jun 19, 2026

Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through th…

CVSS 8.8 · High

CVE-2017-20254

Published Jun 19, 2026

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through…

CVSS 8.8 · High

CVE-2017-20253

Published Jun 19, 2026

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code throug…

CVSS 8.8 · High

CVE-2017-20252

Published Jun 19, 2026

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers…

CVSS 8.8 · High

CVE-2026-12050

Published Jun 19, 2026

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-12045

Published Jun 19, 2026

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privile…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-12044

Published Jun 19, 2026

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-56012

Published Jun 18, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54419

Published Jun 18, 2026

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated S…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-54222

Published Jun 18, 2026

UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to interact with the underlying database. Due to insufficient inpu…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-40455

Published Jun 18, 2026

An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" module due to insufficient sanitization of the POST "tg[]" p…

CVSS 8.6 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-55740

Published Jun 18, 2026

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The b…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-11777

Published Jun 18, 2026

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up…

CVSS 4.9 · Medium
evidence mentions
11
Buzz score
36.4
Showing 451-475 of 19,915 CVEsPage 19 of 797