Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

20,106 CVEs tagged with CWE-894,499 Critical, 8,452 High, 6,191 Medium, 963 Low, 1 Unrated.

CVE-2026-40522

Published Jun 29, 2026

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by…

CVSS 7.1 · High
evidence mentions
4
Buzz score
25.6

CVE-2026-13569

Published Jun 29, 2026

A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processing of the file /index.php of the component API. Such manipul…

CVSS 2.0 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-13566

Published Jun 29, 2026

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /preview3.php. The manipul…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-13565

Published Jun 29, 2026

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_class1.p…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-13559

Published Jun 29, 2026

A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13555

Published Jun 29, 2026

A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?acti…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13552

Published Jun 29, 2026

A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Perf…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13551

Published Jun 29, 2026

A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulat…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13550

Published Jun 29, 2026

A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulatio…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-13548

Published Jun 29, 2026

A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /doctortimings.php. The manipulation of the argument edi…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13542

Published Jun 29, 2026

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13541

Published Jun 29, 2026

A weakness has been identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /doctorchangepassword.php. Executing a manipulation of…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13535

Published Jun 29, 2026

A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13532

Published Jun 29, 2026

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /departmentDoctor.php. This m…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13531

Published Jun 29, 2026

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /department.php. The manipulation of the argument e…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13530

Published Jun 29, 2026

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /appointmentdetail.php of the component Appointment Han…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13529

Published Jun 29, 2026

A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl c…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-13527

Published Jun 29, 2026

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /preview4.php. Such manipulation of…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-13526

Published Jun 29, 2026

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_class.php. This manipulation of the argument ID ca…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-13525

Published Jun 29, 2026

A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13521

Published Jun 29, 2026

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php.…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-13520

Published Jun 29, 2026

A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Ha…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-49048

Published Jun 28, 2026

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13498

Published Jun 28, 2026

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter H…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-13497

Published Jun 28, 2026

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the a…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0
Showing 501-525 of 20,106 CVEsPage 21 of 805