On this page
Atomicorp WAF Rule 341145
Rule Summary
- Rule ID: 341145
- Status: Active
- Alert message: Atomicorp.com WAF Rules: SQL injection probe
- Observed CWEs: CWE-22 (1), CWE-74 (227), CWE-78 (1), CWE-79 (3), CWE-89 (476), CWE-94 (1), CWE-200 (1), CWE-266 (1), CWE-284 (1), CWE-285 (1), CWE-287 (2), CWE-295 (2), CWE-306 (2), CWE-352 (1), CWE-434 (1), CWE-611 (1), CWE-862 (1)
- Revision: 11
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Public tags: SQLi
- Logging: log, auditlog
Description
This rule detects Possible SQL injection probes.
Troubleshooting
False Positives
If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.
Tuning Guidance
If you want to disable this rule, please see the Tuning the Atomicorp WAF Rules page for basic information.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2026-51366 | Bottinelli Informatica Vedo Suite v.1.2.5 Arbitrary Code Execution Vulnerability | Bottinelli Informatica Vedo Suite v.1.2.5 | 9.9 (v3.1) | Critical |
| CVE-2026-69083 | SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent | siyuan | 9.9 (v4.0) | Critical |
| CVE-2026-69084 | SiYuan - SQL Execution | siyuan | 9.9 (v4.0) | Critical |
| CVE-2026-69085 | SiYuan before v3.7.3 SQL Injection via searchDocs | siyuan | 9.9 (v4.0) | Critical |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 9.8 (v3.0) | Critical |
| CVE-2018-6220 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6223 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6228 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2018-6229 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 9.8 (v3.0) | Critical |
| CVE-2019-9083 | SQLiteManager 1.2.0 / 1.2.4 - Blind SQL Injection | sqlitemanager | 9.8 (v3.0) | Critical |
| CVE-2020-24193 | Daily Tracker System 1.0 - Authentication Bypass | daily tracker system | 9.8 (v3.1) | Critical |
| CVE-2020-5307 | PHPGurukul Dairy Farm Shop Management System 1.0 - SQL Injection | dairy farm shop management system | 9.8 (v3.1) | Critical |
| CVE-2020-5722 | Grandstream UCM6200 - SQL Injection | ucm6200 firmware | 9.8 (v3.1) | Critical |
| CVE-2021-40617 | openSIS Community Edition 8.0 - SQL Injection | opensis | 9.8 (v3.1) | Critical |
| CVE-2021-43140 | Simple Subscription Website 1.0 - SQLi Authentication Bypass | simple subscription website | 9.8 (v3.1) | Critical |
| CVE-2021-43510 | Sourcecodester Simple Client Management System 1.0 - SQL Injection | simple client management system | 9.8 (v3.1) | Critical |
| CVE-2022-22897 | PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injection | ap pagebuilder | 9.8 (v3.1) | Critical |
| CVE-2022-27412 | Explore CMS 1.0 - SQL Injection | explore cms | 9.8 (v3.1) | Critical |
| CVE-2022-27927 | Microfinance Management System 1.0 - 'customer_number' SQLi | microfinance management system | 9.8 (v3.1) | Critical |
| CVE-2022-29007 | Dairy Farm Shop Management System 1.0 - SQL Injection | dairy farm shop management system | 9.8 (v3.1) | Critical |
| CVE-2022-29383 | NETGEAR ProSafe SSL VPN firmware - SQL Injection | ssl312 firmware | 9.8 (v3.1) | Critical |
| CVE-2022-31340 | simple inventory system SQL Injection Vulnerability | simple inventory system | 9.8 (v3.1) | Critical |
| CVE-2022-32094 | Hospital Management System 1.0 - SQL Injection | hospital management system | 9.8 (v3.1) | Critical |
| CVE-2022-38637 | Hospital Management System 1.0 - SQL Injection | hospital management system | 9.8 (v3.1) | Critical |
| CVE-2022-40032 | Simple Task Managing System v1.0 - SQL Injection (Unauthenticated) | simple task managing system | 9.8 (v3.1) | Critical |
| CVE-2022-40347 | Intern Record System v1.0 - SQL Injection (Unauthenticated) | intern record system | 9.8 (v3.1) | Critical |
| CVE-2022-46071 | Helmet Store Showroom v1.0 - SQL Injection | helmet store showroom site | 9.8 (v3.1) | Critical |
| CVE-2023-0562 | Bank Locker Management System v1.0 - SQL Injection | bank locker management system | 9.8 (v3.1) | Critical |
| CVE-2023-27847 | PrestaShop xipblog - SQL Injection | xipblog | 9.8 (v3.1) | Critical |
| CVE-2023-34635 | Wifi Soft Unibox Administration 3.0 & 3.1 - SQL Injection | unibox administration | 9.8 (v3.1) | Critical |
| CVE-2023-39650 | PrestaShop Theme Volty CMS Blog - SQL Injection | theme volty cms blog | 9.8 (v3.1) | Critical |
| CVE-2023-40748 | PHPJabbers Food Delivery Script - SQL Injection | food delivery script | 9.8 (v3.1) | Critical |
| CVE-2023-6360 | WordPress My Calendar <3.4.22 - SQL Injection | my calendar | 9.8 (v3.1) | Critical |
| CVE-2024-38289 | TurboMeeting - Boolean-based SQL Injection | turbomeeting | 9.8 (v3.1) | Critical |
| CVE-2024-45622 | ASIS - SQL Injection Authentication Bypass | asis | 9.8 (v3.1) | Critical |
| CVE-2025-57631 | tduck Arbitrary Code Execution Vulnerability | tduck | 9.8 (v3.1) | Critical |
| CVE-2025-67066 | oasys sysoa version 1.0 Arbitrary Code Execution Vulnerability | oasys sysoa version 1.0 | 9.8 (v3.1) | Critical |
| CVE-2025-67403 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-67404 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69930 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69931 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69933 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69934 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69935 | SQL Injection | - | 9.8 (v3.1) | Critical |
| CVE-2025-69936 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69937 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69938 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69941 | SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69942 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69943 | SQL Injection | - | 9.8 (v3.1) | Critical |
| CVE-2025-69947 | SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-70149 | membership management system SQL Injection Vulnerability | membership management system | 9.8 (v3.1) | Critical |
| CVE-2025-70150 | membership management system Missing Authorization Vulnerability | membership management system | 9.8 (v3.1) | Critical |
| CVE-2026-10880 | Unauthenticated SQL Injection in Osnexus Quantastor | QuantaStor | 9.8 (v3.1) | Critical |
| CVE-2026-46670 | YesWiki: Unauthenticated SQL Injection | yeswiki | 9.8 (v3.1) | Critical |
| CVE-2026-48528 | Metacat has an unauthenticated SQL injection vulnerability | metacat | 9.8 (v3.1) | Critical |
| CVE-2026-52472 | Wgcloud 3.6.4 SQL Injection Vulnerability | Wgcloud 3.6.4 | 9.8 (v3.1) | Critical |
| CVE-2026-67689 | FineAdmin V1.0 Arbitrary Code Execution Vulnerability | FineAdmin V1.0 | 9.8 (v3.1) | Critical |
| CVE-2026-68000 | MCMS <=6.2.0 is vulnerable to SQL injection Vulnerability | MCMS <=6.2.0 is vulnerable to SQL injection | 9.8 (v3.1) | Critical |
| CVE-2026-69240 | Sequelize: SQL Injection (Oracle DB) | sequelize | 9.8 (v3.1) | Critical |
| CVE-2026-75330 | super-diamond-server <= 1.3.3 is vulnerable to SQL injection Vulnerability | super-diamond-server <= 1.3.3 is vulnerable to SQL injection | 9.8 (v3.1) | Critical |
| CVE-2026-79569 | Movie_Recommend v1.0.0 SQL Injection Vulnerability | Movie Recommend v1.0.0 | 9.8 (v3.1) | Critical |
| CVE-2026-79570 | mfish-nocode-pro v1.0.0 SQL Injection Vulnerability | mfish-nocode-pro v1.0.0 | 9.8 (v3.1) | Critical |
| CVE-2026-39342 | ChurchCRM has a SQL injection searchwhat parameter via QueryView.php | churchcrm | 9.4 (v4.0) | Critical |
| CVE-2016-20096 | Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp | Linknat VOS3000 | 9.3 (v4.0) | Critical |
| CVE-2025-1023 | ChurchCRM - SQL Injection | churchcrm | 9.3 (v4.0) | Critical |
| CVE-2026-40329 | SQL Injection vulnerability via sortBy in beanFeed | MasaCMS | 9.3 (v4.0) | Critical |
| CVE-2026-40330 | Masa CMS SQL injection via sortDirection parameter in beanFeed | MasaCMS | 9.3 (v4.0) | Critical |
| CVE-2026-63106 | ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php | Ready eCommerce | 9.3 (v4.0) | Critical |
| CVE-2026-81672 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 9.3 (v4.0) | Critical |
| CVE-2026-81673 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 9.3 (v4.0) | Critical |
| CVE-2026-81674 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 9.3 (v4.0) | Critical |
| CVE-2026-81675 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 9.3 (v4.0) | Critical |
| CVE-2026-82526 | R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint | R2R | 9.3 (v4.0) | Critical |
| CVE-2026-9586 | Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection | switchvox | 9.3 (v4.0) | Critical |
| CVE-2025-50455 | the CodeIgniter Query Builder Arbitrary Code Execution Vulnerability | the CodeIgniter Query Builder | 9.1 (v3.1) | Critical |
| CVE-2026-16532 | Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form | Link Library | 9.1 (v3.1) | Critical |
| CVE-2026-73069 | Twenty: SQL Injection in the searchVector Field Settings Allows Arbitrary PostgreSQL Execution | twenty | 9.1 (v3.1) | Critical |
| CVE-2026-72851 | Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook | server | 9.0 (v4.0) | Critical |
| CVE-2017-20243 | WordPress Car Park Booking Plugin SQL Injection via space_id | Car Park Booking System | 8.8 (v4.0) | High |
| CVE-2017-20247 | WordPress Plugin PICA Photo Gallery 1.0 SQL Injection | PICA Photo Gallery | 8.8 (v4.0) | High |
| CVE-2017-20249 | WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection | Apptha Slider Gallery | 8.8 (v4.0) | High |
| CVE-2017-20260 | Joomla! Component Price Alert 3.0.2 SQL Injection | price alert | 8.8 (v4.0) | High |
| CVE-2017-20261 | Joomla! Component Bargain Product VM3 1.0 SQL Injection | bargain product vm3 | 8.8 (v4.0) | High |
| CVE-2017-20263 | Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via location | focalpoint | 8.8 (v4.0) | High |
| CVE-2017-20266 | Joomla SP Movie Database 1.3 SQL Injection via searchword | standard pro movie database | 8.8 (v4.0) | High |
| CVE-2017-20267 | Joomla! Component Calendar Planner 1.0.1 SQL Injection | calendar planner | 8.8 (v4.0) | High |
| CVE-2017-20268 | Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection | zap calendar lite | 8.8 (v4.0) | High |
| CVE-2017-20271 | Joomla StreetGuessr Game 1.1.8 SQL Injection via catid | streetguessr game | 8.8 (v4.0) | High |
| CVE-2017-20272 | Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id | ultimate property listing | 8.8 (v4.0) | High |
| CVE-2017-20273 | Joomla Event Registration Pro Calendar 4.1.3 SQL Injection | event registration pro calendar | 8.8 (v4.0) | High |
| CVE-2017-20274 | Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath | learning management system king | 8.8 (v4.0) | High |
| CVE-2017-20275 | Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter | bridge | 8.8 (v4.0) | High |
| CVE-2017-20276 | Joomla! Component SIMGenealogy 2.1.5 SQL Injection | simgenealogy | 8.8 (v4.0) | High |
| CVE-2017-20277 | Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author | joomla joomrecipe | 8.8 (v4.0) | High |
| CVE-2017-20278 | Joomla JoomRecipe 1.0.3 SQL Injection via category parameter | joomrecipe | 8.8 (v4.0) | High |
| CVE-2017-20279 | Joomla Payage 2.05 SQL Injection via aid Parameter | joomla payage | 8.8 (v4.0) | High |
| CVE-2017-20280 | Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter | myportfolio | 8.8 (v4.0) | High |
| CVE-2017-20281 | Joomla! Component Extra Search 2.2.8 SQL Injection | extra search | 8.8 (v4.0) | High |
| CVE-2017-20282 | Joomla! Component jCart for OpenCart 2.0 SQL Injection | jcart for opencart | 8.8 (v4.0) | High |
| CVE-2018-25340 | Smartshop 1 SQL Injection via category.php | Smartshop | 8.8 (v4.0) | High |
| CVE-2018-25341 | Smartshop 1 SQL Injection via product.php id Parameter | Smartshop | 8.8 (v4.0) | High |
| CVE-2018-25342 | Smartshop 1 SQL Injection via search.php | Smartshop | 8.8 (v4.0) | High |
| CVE-2018-25348 | Joomla! Component Ek Rishta 2.10 SQL Injection via user_detail | Ek Rishta | 8.8 (v4.0) | High |
| CVE-2018-25351 | Joomla! Component EkRishta 2.10 SQL Injection via username | EkRishta | 8.8 (v4.0) | High |
| CVE-2018-25362 | Twitter-Clone 1 SQL Injection via follow.php | PHP-Twitter-Clone | 8.8 (v4.0) | High |
| CVE-2018-25364 | Twitter-Clone 1 SQL Injection via search.php | PHP-Twitter-Clone | 8.8 (v4.0) | High |
| CVE-2018-25371 | mooSocial Store Plugin 2.6 SQL Injection via product parameter | mooSocial Store Plugin | 8.8 (v4.0) | High |
| CVE-2018-25372 | MedDream PACS Server Premium 6.7.1.1 SQL Injection via email | PACS Server Premium | 8.8 (v4.0) | High |
| CVE-2018-25385 | E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai | Registrasi Pencak Silat | 8.8 (v4.0) | High |
| CVE-2018-25394 | Kados R10 GreenBee SQL Injection via update_release.php | Kados R10 GreenBee | 8.8 (v4.0) | High |
| CVE-2018-25395 | Kados R10 GreenBee SQL Injection via update_feature.php | Kados R10 GreenBee | 8.8 (v4.0) | High |
| CVE-2018-25411 | MGB OpenSource Guestbook 0.7.0.2 SQL Injection via email.php | MGB OpenSource Guestbook | 8.8 (v4.0) | High |
| CVE-2018-25414 | AiOPMSD Final 1.0.0 SQL Injection via actor.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25416 | AiOPMSD Final 1.0.0 SQL Injection via country.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25417 | AiOPMSD Final 1.0.0 SQL Injection via quality.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25418 | AiOPMSD Final 1.0.0 SQL Injection via year.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25419 | AiOPMSD Final 1.0.0 SQL Injection via genre.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25420 | AiOPMSD Final 1.0.0 SQL Injection via watch.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25422 | MOGG web simulator Script All Version SQL Injection via play.php | MOGG web simulator Script | 8.8 (v4.0) | High |
| CVE-2018-25424 | Gate Pass Management System 2.1 SQL Injection via login-exec.php | Gate Pass Management System | 8.8 (v4.0) | High |
| CVE-2018-25425 | Yot CMS 3.3.1 SQL Injection via aid and cid Parameters | Yot CMS | 8.8 (v4.0) | High |
| CVE-2018-25428 | Paroiciel 11.20 SQL Injection via tRecIdListe Parameter | Paroiciel | 8.8 (v4.0) | High |
| CVE-2018-25433 | Joomla JE Photo Gallery 1.1 SQL Injection via categoryid | JE Photo Gallery | 8.8 (v4.0) | High |
| CVE-2018-25434 | WP AutoSuggest 0.24 SQL Injection via autosuggest.php | WP AutoSuggest | 8.8 (v4.0) | High |
| CVE-2018-6224 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 8.8 (v3.0) | High |
| CVE-2019-25662 | ResourceSpace 8.6 SQL Injection via watched_searches.php | resourcespace | 8.8 (v4.0) | High |
| CVE-2019-25668 | News Website Script 2.0.5 SQL Injection via index.php | news website script | 8.8 (v4.0) | High |
| CVE-2019-25669 | qdPM 9.1 SQL Injection via search_by_extrafields Parameter | qdpm | 8.8 (v4.0) | High |
| CVE-2019-25675 | eDirectory All Versions SQL Injection Authentication Bypass | edirectory | 8.8 (v4.0) | High |
| CVE-2019-25678 | C4G BLIS 3.4 SQL Injection via users_select.php | computing for good's basic laboratory information system | 8.8 (v4.0) | High |
| CVE-2019-25680 | Advance Gift Shop Pro Script 2.0.3 SQL Injection via search | advance gift shop pro script | 8.8 (v4.0) | High |
| CVE-2019-25684 | OpenDocMan 1.3.4 SQL Injection via where Parameter | opendocman | 8.8 (v4.0) | High |
| CVE-2019-25694 | Kados R10 GreenBee SQL Injection via user2reset | kados | 8.8 (v4.0) | High |
| CVE-2019-25728 | Care2x 2.7 Hospital Information System SQL Injection via ck_config | Care2x | 8.8 (v4.0) | High |
| CVE-2019-25730 | Listing Hub CMS 1.0 SQL Injection via pages.php id | Listing Hub CMS | 8.8 (v4.0) | High |
| CVE-2019-25732 | PHP EI-Tube Script 3 SQL Injection via search parameter | EI-Tube | 8.8 (v4.0) | High |
| CVE-2019-25745 | WordPress Plugin Google Review Slider 6.1 SQL Injection via tid | Google Review Slider | 8.8 (v4.0) | High |
| CVE-2019-25748 | Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels | jhotelreservation | 8.8 (v4.0) | High |
| CVE-2019-25750 | Joomla J-MultipleHotelReservation 6.0.7 SQL Injection | multiplehotelreservation | 8.8 (v4.0) | High |
| CVE-2019-25751 | Joomla J-ClassifiedsManager 3.0.5 SQL Injection | classifiedsmanager | 8.8 (v4.0) | High |
| CVE-2019-25752 | Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection | j-businessdirectory | 8.8 (v4.0) | High |
| CVE-2019-25756 | Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard | vaccount | 8.8 (v4.0) | High |
| CVE-2020-15876 | SQL Injection | - | 8.8 (v3.1) | High |
| CVE-2020-15878 | SQL Injection | - | 8.8 (v3.1) | High |
| CVE-2020-5504 | phpMyAdmin 5.0.0 - SQL Injection | phpmyadmin | 8.8 (v3.1) | High |
| CVE-2021-47928 | Opencart TMD Vendor System 3.x Blind SQL Injection via product route | Extension TMD Vendor System | 8.8 (v4.0) | High |
| CVE-2021-47930 | Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated | Balbooa Joomla Forms Builder | 8.8 (v4.0) | High |
| CVE-2022-28080 | Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated) | event management system | 8.8 (v3.1) | High |
| CVE-2024-36597 | AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability. | life insurance management system | 8.8 (v3.1) | High |
| CVE-2025-45868 | LogicalDOC Enterprise up to and for v9.1.1 SQL Injection Vulnerability | - | 8.8 (v3.1) | High |
| CVE-2026-31069 | BillaBear (all versions prior to Jan 2026) SQL Injection Vulnerability | BillaBear (all versions prior to Jan 2026) | 8.8 (v3.1) | High |
| CVE-2026-35395 | WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameter | wegia | 8.8 (v3.1) | High |
| CVE-2026-35470 | OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals | openstamanager | 8.8 (v3.1) | High |
| CVE-2026-41075 | RT: SQL injection via entry_aggregator parameter in JSON search | rt | 8.8 (v3.1) | High |
| CVE-2026-52775 | YesWiki Authenticated SQL Injection in ReactionManager | yeswiki | 8.8 (v3.1) | High |
| CVE-2026-55509 | WsgiDAV: Blind SQL injection in the MySQL provider | wsgidav | 8.8 (v4.0) | High |
| CVE-2026-70370 | Koha - SQL Injection in reports/catalogue_stats.pl | Koha | 8.8 (v3.1) | High |
| CVE-2026-70373 | Koha - SQL Injection in reports/issues_stats.pl | Koha | 8.8 (v3.1) | High |
| CVE-2026-81676 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 8.8 (v4.0) | High |
| CVE-2026-81677 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 8.8 (v4.0) | High |
| CVE-2016-20097 | Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad | E-cology 8.0 | 8.7 (v4.0) | High |
| CVE-2019-25765 | ASP-CMS SQL Injection via commentList.asp id Parameter | ASP-CMS | 8.7 (v4.0) | High |
| CVE-2022-50997 | Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp | E-cology 9.0 | 8.7 (v4.0) | High |
| CVE-2024-58374 | Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree | e-HR | 8.7 (v4.0) | High |
| CVE-2026-23921 | Blind, read-only SQL injection in Zabbix API via sortfield parameter | zabbix | 8.7 (v4.0) | High |
| CVE-2026-27634 | Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter | piwigo | 8.7 (v4.0) | High |
| CVE-2026-31844 | Authenticated SQL Injection in Koha displayby parameter of suggestion.pl | koha | 8.7 (v4.0) | High |
| CVE-2026-34100 | Guardian Language-System SQL Injection via id Parameter in media.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34101 | Guardian Language-System SQL Injection via id Parameter in text_file.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34102 | Guardian Language-System SQL Injection via id Parameter in job_info_get.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34103 | Guardian Language-System SQL Injection via id Parameter in subtitles.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34104 | Guardian Language-System SQL Injection via name Parameter in designer.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34105 | Guardian Language-System SQL Injection via id Parameter in translate_text.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-35184 | EcclesiaCRM has a Critical SQL Injection | ecclesiacrm | 8.7 (v4.0) | High |
| CVE-2026-41453 | Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter | laravel-crm | 8.7 (v4.0) | High |
| CVE-2026-44886 | Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection | Pi.Alert | 8.7 (v4.0) | High |
| CVE-2026-50636 | LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection | LimeSurvey | 8.7 (v4.0) | High |
| CVE-2026-61518 | ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter | ispconfig3 | 8.7 (v4.0) | High |
| CVE-2026-72708 | SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter | SPIP | 8.7 (v4.0) | High |
| CVE-2026-82655 | Admidio before 5.0.12 SQL Injection via relation_type_list | admidio | 8.7 (v4.0) | High |
| CVE-2026-84208 | AVideo User_Location Plugin Unauthenticated SQL Injection | AVideo | 8.7 (v4.0) | High |
| CVE-2026-85155 | WWBN AVideo SQL Injection via get.json.php APIName channels | AVideo | 8.7 (v4.0) | High |
| CVE-2026-87807 | siyuan before v3.8.2 SQL Injection via fullTextSearchBlock | siyuan | 8.7 (v4.0) | High |
| CVE-2026-12721 | Kirki < 6.0.13 - Unauthenticated SQL Injection | Kirki | 8.6 (v3.1) | High |
| CVE-2026-16061 | Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name} | Rest Routes | 8.6 (v3.1) | High |
| CVE-2026-3326 | XStore Theme < 9.7.3 - SQL Injection | Xstore | 8.6 (v3.1) | High |
| CVE-2026-39931 | OpenEMR Authenticated SQL Injection via backup.php Import Feature | openemr | 8.6 (v4.0) | High |
| CVE-2026-76635 | baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php | basercms | 8.6 (v4.0) | High |
| CVE-2026-79322 | mageplaza blog SQL Injection Vulnerability | mageplaza blog | 8.6 (v3.1) | High |
| CVE-2026-81728 | Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys | dolibarr erp/crm | 8.6 (v4.0) | High |
| CVE-2026-44238 | FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports | freepbx | 8.5 (v4.0) | High |
| CVE-2026-44706 | Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values | chatwoot | 8.5 (v3.1) | High |
| CVE-2026-65707 | Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint | likeshop | 8.5 (v4.0) | High |
| CVE-2026-49489 | OpenCATS - SQL Injection in DataGrid sortDirection Parameter | OpenCATS | 8.4 (v4.0) | High |
| CVE-2026-64657 | Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL | budibase | 8.4 (v3.1) | High |
| CVE-2026-88890 | OpenPanel SQL Injection via unvalidated profile filter column identifier | openpanel | 8.4 (v4.0) | High |
| CVE-2026-52771 | YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (ApiController::deletePage) | yeswiki | 8.3 (v3.1) | High |
| CVE-2026-14920 | AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter | AcyMailing | 8.2 (v3.1) | High |
| CVE-2018-6221 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 8.1 (v3.0) | High |
| CVE-2026-15258 | Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter | Product Feed Manager For WooCommerce | 8.1 (v3.1) | High |
| CVE-2026-39341 | SQL injection in ChurchCRM.0 | churchcrm | 8.1 (v3.1) | High |
| CVE-2018-6222 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 7.8 (v3.0) | High |
| CVE-2014-9145 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v2.0) | High |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v3.0) | High |
| CVE-2020-22165 | PHPGurukul Hospital Management System 4.0 - SQL Injection | hospital management system | 7.5 (v3.1) | High |
| CVE-2021-37589 | Virtua Software Cobranca 12S - SQLi | cobranca | 7.5 (v3.1) | High |
| CVE-2023-32590 | Subscribe to Category <= 2.7.4 - SQL Injection | subscribe to category | 7.5 (v3.1) | High |
| CVE-2026-10716 | Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation | Directus | 7.5 (v4.0) | High |
| CVE-2026-3018 | WordPress Newsletters <= 4.13 - Unauthenticated SQL Injection | Newsletters | 7.5 (v3.1) | High |
| CVE-2026-52476 | aiflowy <= 2.1.2 SQL Injection Vulnerability | aiflowy <= 2.1.2 | 7.5 (v3.1) | High |
| CVE-2026-52770 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki | yeswiki | 7.5 (v3.1) | High |
| CVE-2025-67405 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-67406 | Advocate office management system Arbitrary Code Execution Vulnerability | Advocate office management system | 7.3 (v3.1) | High |
| CVE-2025-67407 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-67408 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-69944 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-69945 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-69949 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2022-31339 | simple inventory system SQL Injection Vulnerability | simple inventory system | 7.2 (v3.1) | High |
| CVE-2026-27834 | Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter | piwigo | 7.2 (v3.1) | High |
| CVE-2026-27885 | Piwigo: SQL Injection in Activity.getList | piwigo | 7.2 (v3.1) | High |
| CVE-2026-39343 | ChurchCRM has a SQL Injection in Event Type Editor (Admin) | churchcrm | 7.2 (v3.1) | High |
| CVE-2018-25392 | MaxOn ERP Software 8.x-9.x SQL Injection via nomor Parameter | MaxOn ERP | 7.1 (v4.0) | High |
| CVE-2018-25429 | Paroiciel 11.20 SQL Injection via zProIdPro Parameter | Paroiciel | 7.1 (v4.0) | High |
| CVE-2018-25430 | Paroiciel 11.20 SQL Injection via eGeqIdEquipe Parameter | Paroiciel | 7.1 (v4.0) | High |
| CVE-2018-25431 | No-Cms 1.0 SQL Injection via order_by Parameter | No-CMS | 7.1 (v4.0) | High |
| CVE-2019-25664 | SuiteCRM 7.10.7 SQL Injection via record Parameter | suitecrm | 7.1 (v4.0) | High |
| CVE-2019-25749 | Joomla J-CruisePortal 6.0.4 SQL Injection via cruises | j-cruiseportal | 7.1 (v4.0) | High |
| CVE-2019-25761 | Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id | joomcrm | 7.1 (v4.0) | High |
| CVE-2026-16007 | Authenticated SQL Injection in AppFlowy | AppFlowy-Cloud | 7.1 (v4.0) | High |
| CVE-2026-18737 | Shlink Blind SQL Injection via tags/stats orderBy Parameter | Shlink | 7.1 (v4.0) | High |
| CVE-2026-33714 | Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2) | chamilo lms | 7.1 (v4.0) | High |
| CVE-2026-48231 | Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48232 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset Parameter | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48233 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset Parameter | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48234 | Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48236 | Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48237 | Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48238 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48239 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48240 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-63080 | Aptabase SQL Injection via ClickHouse query backend | aptabase | 7.1 (v4.0) | High |
| CVE-2026-72607 | Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by Age | Koha | 7.1 (v3.1) | High |
| CVE-2026-72609 | Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl | Koha | 7.1 (v3.1) | High |
| CVE-2026-75132 | WAPT Server SQL Injection via /api/v3/hosts Endpoint | WAPT | 7.1 (v4.0) | High |
| CVE-2026-69704 | Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() | Atals-Livre | 7.0 (v4.0) | High |
| CVE-2025-2473 | Company Visitor Management System 1.0 - SQL Injection | company visitor management system | 6.9 (v4.0) | Medium |
| CVE-2018-6230 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 6.8 (v3.0) | Medium |
| CVE-2018-6219 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 6.5 (v3.0) | Medium |
| CVE-2021-39165 | Cachet <=2.3.18 - SQL Injection | cachet | 6.5 (v3.1) | Medium |
| CVE-2023-27167 | Suprema BioStar 2 v2.8.16 - SQL Injection | biostar 2 | 6.5 (v3.1) | Medium |
| CVE-2026-34788 | Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parameters | emlog | 6.5 (v3.1) | Medium |
| CVE-2026-39229 | Bolt CMS through 3.7.0 SQL Injection Vulnerability | - | 6.5 (v3.1) | Medium |
| CVE-2026-72608 | Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name | Koha | 6.5 (v3.1) | Medium |
| CVE-2025-9744 | Loan Management System 1.0 - SQL Injection | online loan management system | 5.5 (v4.0) | Medium |
| CVE-2026-10178 | code-projects Online Music Site AdminEditAlbum.php sql injection | Online Music Site | 5.5 (v4.0) | Medium |
| CVE-2026-10186 | code-projects Online Hospital Management System patient.php sql injection | Online Hospital Management System | 5.5 (v4.0) | Medium |
| CVE-2026-10251 | itsourcecode Online House Rental System ajax.php login sql injection | Online House Rental System | 5.5 (v4.0) | Medium |
| CVE-2026-10252 | itsourcecode Online House Rental System manage_tenant.php sql injection | Online House Rental System | 5.5 (v4.0) | Medium |
| CVE-2026-10253 | itsourcecode Online House Rental System manage_payment.php sql injection | Online House Rental System | 5.5 (v4.0) | Medium |
| CVE-2026-10261 | CodeAstro Online Job Portal application_status.php sql injection | Online Job Portal | 5.5 (v4.0) | Medium |
| CVE-2026-10262 | code-projects Real State Services Login loginuser.php sql injection | Real State Services | 5.5 (v4.0) | Medium |
| CVE-2026-10620 | code-projects Student Admission System index.php sql injection | Student Admission System | 5.5 (v4.0) | Medium |
| CVE-2026-11435 | Jinher OA nextselectplan.aspx sql injection | OA | 5.5 (v4.0) | Medium |
| CVE-2026-11456 | Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection | CRM | 5.5 (v4.0) | Medium |
| CVE-2026-11482 | SourceCodester Class and Exam Timetabling System archive5.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11483 | SourceCodester Class and Exam Timetabling System archive4.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11484 | SourceCodester Class and Exam Timetabling System archive3.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11485 | SourceCodester Class and Exam Timetabling System archive2.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11486 | SourceCodester Class and Exam Timetabling System archive1.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11488 | code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection | Simple Flight Ticket Booking System | 5.5 (v4.0) | Medium |
| CVE-2026-11489 | code-projects Online Music Site AdminDeleteAlbum.php sql injection | Online Music Site | 5.5 (v4.0) | Medium |
| CVE-2026-11490 | code-projects Online Music Site Search.php sql injection | Online Music Site | 5.5 (v4.0) | Medium |
| CVE-2026-11501 | SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection | Hospitals Patient Records Management System | 5.5 (v4.0) | Medium |
| CVE-2026-11582 | CodeAstro Student Attendance Management System index.php sql injection | Student Attendance Management System | 5.5 (v4.0) | Medium |
| CVE-2026-16152 | SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16154 | SourceCodester Class and Exam Timetabling System edit_room1.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16227 | SourceCodester Class and Exam Timetabling System edit_subject.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16228 | SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16484 | SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16765 | CodeAstro Online Classroom loginlinkadmin.php sql injection | Online Classroom | 5.5 (v4.0) | Medium |
| CVE-2026-19021 | SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection | Computer Repair Shop Management System | 5.5 (v4.0) | Medium |
| CVE-2026-19196 | SourceCodester Photo Share Website ajax.php login sql injection | Photo Share Website | 5.5 (v4.0) | Medium |
| CVE-2026-19211 | SourceCodester Photo Share Website ajax.php signup sql injection | Photo Share Website | 5.5 (v4.0) | Medium |
| CVE-2026-19344 | code-projects Task Management System comment_count_user.php sql injection | Task Management System | 5.5 (v4.0) | Medium |
| CVE-2026-19899 | SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-19919 | code-projects Online Shopping System Login login.php sql injection | Online Shopping System | 5.5 (v4.0) | Medium |
| CVE-2026-19926 | Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection | Evergreen | 5.5 (v4.0) | Medium |
| CVE-2026-5368 | projectworlds Car Rental Project Parameter login.php sql injection | car rental project | 5.5 (v4.0) | Medium |
| CVE-2026-5554 | code-projects Concert Ticket Reservation System Parameter process_search.php sql injection | Concert Ticket Reservation System | 5.5 (v4.0) | Medium |
| CVE-2026-5555 | code-projects Concert Ticket Reservation System Parameter login.php sql injection | Concert Ticket Reservation System | 5.5 (v4.0) | Medium |
| CVE-2026-5564 | code-projects Simple Laundry System Parameter searchguest.php sql injection | Simple Laundry System | 5.5 (v4.0) | Medium |
| CVE-2026-5565 | code-projects Simple Laundry System Parameter delmemberinfo.php sql injection | Simple Laundry System | 5.5 (v4.0) | Medium |
| CVE-2026-5575 | SourceCodester/jkev Record Management System Login index.php sql injection | Record Management System | 5.5 (v4.0) | Medium |
| CVE-2026-5577 | Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection | cross browser fingerprinting | 5.5 (v4.0) | Medium |
| CVE-2026-5634 | projectworlds Car Rental Project Parameter book_car.php sql injection | Car Rental Project | 5.5 (v4.0) | Medium |
| CVE-2026-5672 | code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection | Simple IT Discussion Forum | 5.5 (v4.0) | Medium |
| CVE-2026-5805 | code-projects Easy Blog Site contact_us.php sql injection | Easy Blog Site | 5.5 (v4.0) | Medium |
| CVE-2026-5813 | PHPGurukul Online Course Registration check_availability.php sql injection | Online Course Registration | 5.5 (v4.0) | Medium |
| CVE-2026-5824 | code-projects Simple Laundry System userchecklogin.php sql injection | Simple Laundry System | 5.5 (v4.0) | Medium |
| CVE-2026-7194 | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection | Pharmacy Sales and Inventory System | 5.5 (v4.0) | Medium |
| CVE-2026-75079 | SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-75080 | SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-75089 | PHPGurukul Complaint Management System check_availability.php sql injection | Complaint Management System | 5.5 (v4.0) | Medium |
| CVE-2026-75778 | code-projects Task Management System Login Form index.php select_with_multiple_condition sql injection | Task Management System | 5.5 (v4.0) | Medium |
| CVE-2026-75986 | code-projects Online Job Portal System Password Recovery ForPass.php sql injection | Online Job Portal System | 5.5 (v4.0) | Medium |
| CVE-2026-76574 | code-projects Hospital Information System User Login UsersController.php login sql injection | Hospital Information System | 5.5 (v4.0) | Medium |
| CVE-2026-76762 | code-projects Assessment Management welcome.php sql injection | Assessment Management | 5.5 (v4.0) | Medium |
| CVE-2026-76764 | code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection | Employee Management System | 5.5 (v4.0) | Medium |
| CVE-2026-76990 | code-projects Simple Inventory System delete.php sql injection | Simple Inventory System | 5.5 (v4.0) | Medium |
| CVE-2026-77019 | CodeAstro Apartment Visitor Management System forgotpw.php sql injection | Apartment Visitor Management System | 5.5 (v4.0) | Medium |
| CVE-2026-77020 | CodeAstro Apartment Visitor Management System password-recovery.php sql injection | Apartment Visitor Management System | 5.5 (v4.0) | Medium |
| CVE-2026-78143 | code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection | Barangay Resident Profiling Management System | 5.5 (v4.0) | Medium |
| CVE-2026-78171 | itsourcecode Sales and Inventory System processlogin.php sql injection | Sales and Inventory System | 5.5 (v4.0) | Medium |
| CVE-2026-78199 | SourceCodester Simple Online Food Ordering System view_prod.php sql injection | Simple Online Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-78201 | itsourcecode Payroll System admin_class.php login sql injection | Payroll System | 5.5 (v4.0) | Medium |
| CVE-2026-78244 | itsourcecode Real Estate Management System search.php sql injection | Real Estate Management System | 5.5 (v4.0) | Medium |
| CVE-2026-78246 | itsourcecode Online Clinic Management System Admin Login login.php sql injection | Online Clinic Management System | 5.5 (v4.0) | Medium |
| CVE-2026-79804 | SililaWijesinghe Food Ordering System search.php sql injection | Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-79845 | code-projects Simple Inventory System edit.php sql injection | Simple Inventory System | 5.5 (v4.0) | Medium |
| CVE-2026-82600 | SeaCMS zyapi.php sql injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-82610 | itsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82611 | itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82612 | itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82613 | itsourcecode Online Medicine Delivery System Product Search index.php loadResultList sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82614 | itsourcecode Online Medicine Delivery System Product Category Filter index.php loadResultList sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82615 | itsourcecode Online Medicine Delivery System Password Recovery passwordrecover.php find_phone sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82701 | code-projects Online Shopping System Search Functionality action.php sql injection | Online Shopping System | 5.5 (v4.0) | Medium |
| CVE-2026-84111 | Chanjet CRM jxf_dump_table.php sql injection | CRM | 5.5 (v4.0) | Medium |
| CVE-2026-85187 | itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-85225 | code-projects Doctor Appointment System patient_login.php sql injection | Doctor Appointment System | 5.5 (v4.0) | Medium |
| CVE-2026-85379 | light0011 cms Query Builder ChapterController.class.php searchChapter sql injection | cms | 5.5 (v4.0) | Medium |
| CVE-2026-85397 | code-projects Hospital Information System addReq.php findBySearch sql injection | Hospital Information System | 5.5 (v4.0) | Medium |
| CVE-2026-85398 | code-projects Hospital Information System viewReq.php viewReq sql injection | Hospital Information System | 5.5 (v4.0) | Medium |
| CVE-2026-85399 | code-projects Hospital Information System PrespController.php getSinglePresp sql injection | Hospital Information System | 5.5 (v4.0) | Medium |
| CVE-2026-85402 | code-projects Doctor Appointment System booking.php sql injection | Doctor Appointment System | 5.5 (v4.0) | Medium |
| CVE-2026-85403 | code-projects Doctor Appointment System contactus.php sql injection | Doctor Appointment System | 5.5 (v4.0) | Medium |
| CVE-2026-85516 | code-projects Vehicle Management System busprofile.php sql injection | Vehicle Management System | 5.5 (v4.0) | Medium |
| CVE-2026-86159 | SourceCodester Online Voting System ajax.php save_user sql injection | Online Voting System | 5.5 (v4.0) | Medium |
| CVE-2026-86160 | SourceCodester Online Voting System ajax.php delete_voting sql injection | Online Voting System | 5.5 (v4.0) | Medium |
| CVE-2026-86161 | SourceCodester Online Voting System ajax.php delete_category sql injection | Online Voting System | 5.5 (v4.0) | Medium |
| CVE-2026-86162 | SourceCodester Online Voting System ajax.php login sql injection | Online Voting System | 5.5 (v4.0) | Medium |
| CVE-2026-86168 | code-projects Content Management System login.php sql injection | Content Management System | 5.5 (v4.0) | Medium |
| CVE-2026-86180 | code-projects Task Management System In PHP Login index.php sql injection | Task Management System In PHP | 5.5 (v4.0) | Medium |
| CVE-2026-86211 | rabindralamsal inventory-management-system Login index.php sql injection | inventory-management-system | 5.5 (v4.0) | Medium |
| CVE-2026-86213 | Mstfakts College-Management-System Search university.php mysqli_query sql injection | College-Management-System | 5.5 (v4.0) | Medium |
| CVE-2026-86268 | itsourcecode School Management System User_Login.php sql injection | School Management System | 5.5 (v4.0) | Medium |
| CVE-2026-86290 | SourceCodester Online Voting System ajax.php save_category sql injection | Online Voting System | 5.5 (v4.0) | Medium |
| CVE-2026-86298 | SourceCodester Class and Exam Timetabling System delete_subject.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-9355 | SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injection | Hospitals Patient Records Management System | 5.5 (v4.0) | Medium |
| CVE-2026-9469 | yashpokharna2555 StudentManagementSystem success.php sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2026-9470 | yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2026-9584 | code-projects Project Management System Login chk.php sql injection | Project Management System | 5.5 (v4.0) | Medium |
| CVE-2026-9606 | itsourcecode Courier Management System manage_user.php sql injection | Courier Management System | 5.5 (v4.0) | Medium |
| CVE-2018-6226 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 5.4 (v3.0) | Medium |
| CVE-2018-6227 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 5.4 (v3.0) | Medium |
| CVE-2026-30520 | loan management system SQL Injection Vulnerability | loan management system | 5.4 (v3.1) | Medium |
| CVE-2026-38467 | the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerability | the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 | 5.4 (v3.1) | Medium |
| CVE-2026-47720 | FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString | FUXA | 5.3 (v3.1) | Medium |
| CVE-2026-5606 | PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection | Online Shopping Portal Project | 5.3 (v4.0) | Medium |
| CVE-2026-78864 | liketrek TREK Journey Entry Update journey.controller.t journeyService.updateEntry sql injection | TREK | 5.3 (v4.0) | Medium |
| CVE-2026-85205 | itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injection | Online Medicine Delivery System | 5.3 (v4.0) | Medium |
| CVE-2026-9524 | xianrendzw EasyReport REST Endpoint execute sql injection | EasyReport | 5.3 (v4.0) | Medium |
| CVE-2014-9146 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 4.3 (v2.0) | Medium |
| CVE-2018-6225 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | 4.3 (v3.0) | Medium |
| CVE-2026-38468 | the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerability | the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 | 4.3 (v3.1) | Medium |
| CVE-2026-72610 | Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation | Koha | 4.3 (v3.1) | Medium |
| CVE-2026-14238 | Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report | vitepos | 4.1 (v3.1) | Medium |
| CVE-2014-1222 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | vtiger crm | 4.0 (v2.0) | Medium |
| CVE-2025-10592 | itsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injection | online public access catalog | 2.1 (v4.0) | Low |
| CVE-2025-13811 | jsnjfz WebStack-Guns PageFactory.java sql injection | webstack-guns | 2.1 (v4.0) | Low |
| CVE-2026-10170 | code-projects Visitor Management System phone_0.php sql injection | Visitor Management System | 2.1 (v4.0) | Low |
| CVE-2026-10209 | code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection | Online Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-10256 | itsourcecode Content Management System save_comment.php sql injection | Content Management System | 2.1 (v4.0) | Low |
| CVE-2026-10286 | CodeAstro Payroll System home_employee.php sql injection | Payroll System | 2.1 (v4.0) | Low |
| CVE-2026-10296 | itsourcecode Fees Management System ajax.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10297 | itsourcecode Fees Management System manage_course.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10302 | itsourcecode Fees Management System manage_fee.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10568 | itsourcecode Fees Management System manage_payment.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10808 | itsourcecode Fees Management System manage_student.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10809 | itsourcecode Fees Management System manage_user.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10811 | itsourcecode Fees Management System receipt.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-11412 | Jinher OA GetFormSn.aspx sql injection | OA | 2.1 (v4.0) | Low |
| CVE-2026-11475 | Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection | student-management-system | 2.1 (v4.0) | Low |
| CVE-2026-11476 | Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization | student-management-system | 2.1 (v4.0) | Low |
| CVE-2026-11495 | CodeAstro Ingredients Stock Management System add_stock.php sql injection | Ingredients Stock Management System | 2.1 (v4.0) | Low |
| CVE-2026-11513 | itsourcecode Hospital Management System adminaccount.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-11514 | itsourcecode Hospital Management System addpatient.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-11558 | CodeAstro Payroll System home_salary.php sql injection | Payroll System | 2.1 (v4.0) | Low |
| CVE-2026-11559 | CodeAstro Payroll System view_account.php sql injection | Payroll System | 2.1 (v4.0) | Low |
| CVE-2026-11583 | CodeAstro Student Attendance Management System createClass.php sql injection | Student Attendance Management System | 2.1 (v4.0) | Low |
| CVE-2026-11584 | CodeAstro Student Attendance Management System createClass.php edit sql injection | Student Attendance Management System | 2.1 (v4.0) | Low |
| CVE-2026-11585 | CodeAstro Student Attendance Management System createClassArms.php sql injection | Student Attendance Management System | 2.1 (v4.0) | Low |
| CVE-2026-16131 | itsourcecode Hospital Management System prescriptionrecord.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-16244 | itsourcecode Hospital Management System prescriptionorderreport.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-16334 | itsourcecode Hospital Management System prescriptionorder.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-16449 | zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection | ZS-Admin | 2.1 (v4.0) | Low |
| CVE-2026-18766 | chetans9 core-php-admin-panel customers.php sql injection | core-php-admin-panel | 2.1 (v4.0) | Low |
| CVE-2026-18896 | lavkush-maurya Student-Registration-System changepass.php sql injection | Student-Registration-System | 2.1 (v4.0) | Low |
| CVE-2026-19020 | itsourcecode Hospital Management System servicetype.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19067 | itsourcecode Hospital Management System treatment.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19068 | itsourcecode Hospital Management System treatmentdetail.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19069 | itsourcecode Hospital Management System treatmentrecord.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19070 | itsourcecode Hospital Management System viewadmin.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19071 | itsourcecode Hospital Management System viewappointment.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19347 | itsourcecode Hospital Management System viewdoctor.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19364 | itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19767 | itsourcecode Hospital Management System viewdoctortimings.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19894 | itsourcecode Hospital Management System viewmedicine.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19917 | code-projects Online Food Order System delete_food_items1.php sql injection | Online Food Order System | 2.1 (v4.0) | Low |
| CVE-2026-19920 | code-projects Online Shopping System action.php sql injection | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-19921 | code-projects Online Shopping System homeaction.php sql injection | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-19923 | code-projects Online Shopping System checkout_process.php sql injection | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-19934 | itsourcecode Hospital Management System vieworder.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19972 | itsourcecode Hospital Management System viewpatient.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19973 | itsourcecode Hospital Management System viewpaymentreport.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-20000 | itsourcecode Hospital Management System viewprescriptionrecord.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-5206 | code-projects Simple Gym Management System Payment sql injection | Simple Gym Management System | 2.1 (v4.0) | Low |
| CVE-2026-5537 | halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection | CourseSEL | 2.1 (v4.0) | Low |
| CVE-2026-5552 | PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5553 | itsourcecode Online Cellphone System Parameter available.php sql injection | Online Cellphone System | 2.1 (v4.0) | Low |
| CVE-2026-5558 | PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection | PHPGurukul Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5560 | PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5578 | CodeAstro Online Classroom Parameter addassessment.php sql injection | Online Classroom | 2.1 (v4.0) | Low |
| CVE-2026-5579 | CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection | Online Classroom | 2.1 (v4.0) | Low |
| CVE-2026-5580 | CodeAstro Online Classroom Parameter addvideos.php sql injection | Online Classroom | 2.1 (v4.0) | Low |
| CVE-2026-5583 | PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5620 | itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection | Construction Management System | 2.1 (v4.0) | Low |
| CVE-2026-5635 | PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5636 | PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5675 | itsourcecode Construction Management System Parameter borrowed_tool.php sql injection | Construction Management System | 2.1 (v4.0) | Low |
| CVE-2026-5681 | itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection | sanitize or validate this input | 2.1 (v4.0) | Low |
| CVE-2026-5719 | itsourcecode Construction Management System borrowedtool.php sql injection | Construction Management System | 2.1 (v4.0) | Low |
| CVE-2026-5823 | itsourcecode Construction Management System borrowed_tool_report.php sql injection | Construction Management System | 2.1 (v4.0) | Low |
| CVE-2026-7196 | CodeAstro Online Classroom guestdetails sql injection | Online Classroom | 2.1 (v4.0) | Low |
| CVE-2026-75086 | itsourcecode Hospital Management System viewroom.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-75087 | itsourcecode Hospital Management System viewdepartment.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-75088 | itsourcecode Hospital Management System viewbilling.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-75876 | xianrendzw EasyReport Move Operations ModuleController.java sql injection | EasyReport | 2.1 (v4.0) | Low |
| CVE-2026-76785 | amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injection | Mini-Inventory-and-Sales-Management-System | 2.1 (v4.0) | Low |
| CVE-2026-76991 | itsourcecode Hospital Management System viewappointmentapproved.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-77025 | itsourcecode Hospital Management System viewappointmentpending.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-78056 | sambitraj Student-Management-System Dashboard sql injection | Student-Management-System | 2.1 (v4.0) | Low |
| CVE-2026-78057 | sambitraj Student-Management-System Management Mutation sql injection | Student-Management-System | 2.1 (v4.0) | Low |
| CVE-2026-78112 | itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection | Hospital Management System Project in PHP | 2.1 (v4.0) | Low |
| CVE-2026-78185 | itsourcecode Sales and Inventory System cust_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-78200 | itsourcecode Library Management System editbooks.php sql injection | Library Management System | 2.1 (v4.0) | Low |
| CVE-2026-78656 | itsourcecode Sales and Inventory System cust_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-8231 | CodeAstro Online Catering Ordering System deleteorder.php sql injection | Online Catering Ordering System | 2.1 (v4.0) | Low |
| CVE-2026-82421 | itsourcecode Sales and Inventory System emp_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82422 | itsourcecode Sales and Inventory System emp_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82424 | PHPGurukul Student Information System student_edit1.php sql injection | Student Information System | 2.1 (v4.0) | Low |
| CVE-2026-82484 | itsourcecode Sales and Inventory System emp_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82485 | itsourcecode Sales and Inventory System pro_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82540 | itsourcecode Sales and Inventory System cust_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82541 | itsourcecode Sales and Inventory System sup_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82545 | itsourcecode Sales and Inventory System sup_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82609 | itsourcecode Sales and Inventory System inv_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82696 | itsourcecode Sales and Inventory System inv_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-84109 | Xinhu Rainrock RockOA webmainAction.php getOrder sql injection | Rainrock RockOA | 2.1 (v4.0) | Low |
| CVE-2026-84153 | Xinhu Rainrock RockOA index.php toaddval sql injection | Rainrock RockOA | 2.1 (v4.0) | Low |
| CVE-2026-85383 | itsourcecode Sales and Inventory System inv_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86163 | itsourcecode Sales and Inventory System pro_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86164 | itsourcecode Sales and Inventory System trans_view.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86170 | DefaultFuction CRM edit.php sql injection | CRM | 2.1 (v4.0) | Low |
| CVE-2026-86171 | DefaultFuction CRM delete.php sql injection | CRM | 2.1 (v4.0) | Low |
| CVE-2026-86172 | DefaultFuction CRM delete.php sql injection | CRM | 2.1 (v4.0) | Low |
| CVE-2026-86232 | itsourcecode Sales and Inventory System sup_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86233 | itsourcecode Sales and Inventory System us_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86234 | itsourcecode Sales and Inventory System cust_transac.php add sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86235 | itsourcecode Sales and Inventory System pos_transac.php add sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86236 | itsourcecode Sales and Inventory System pro_transac.php add sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86245 | itsourcecode Sales and Inventory System sup_transac.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86265 | itsourcecode Sales and Inventory System us_transac.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86267 | itsourcecode Information System Society Membership System check_student.php sql injection | Information System Society Membership System | 2.1 (v4.0) | Low |
| CVE-2026-86269 | itsourcecode Sales and Inventory System emp_edit1.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86270 | itsourcecode Sales and Inventory System settings_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86291 | itsourcecode Sales and Inventory System us_edit1.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86309 | itsourcecode Sales and Inventory System pro_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86310 | itsourcecode Sales and Inventory System cust_edit1.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86517 | itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86518 | code-projects Student Crud Operation edit.php sql injection | Student Crud Operation | 2.1 (v4.0) | Low |
| CVE-2026-86675 | itsourcecode Sales and Inventory System us_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-9450 | code-projects Employee Management System psubmit.php sql injection | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9451 | code-projects Employee Management System applyleaveprocess.php sql injection | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9607 | itsourcecode Courier Management System parcel_list.php sql injection | Courier Management System | 2.1 (v4.0) | Low |
| CVE-2026-10155 | Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection | Multi-Store Inventory Management System | 2.0 (v4.0) | Low |
| CVE-2026-10171 | code-projects Online Music Site AdminUpdateAlbum.php sql injection | Online Music Site | 2.0 (v4.0) | Low |
| CVE-2026-19787 | SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection | Air Cargo Management System | 2.0 (v4.0) | Low |
| CVE-2026-19925 | SourceCodester Stock Management System Master.php delete_supplier sql injection | Stock Management System | 2.0 (v4.0) | Low |
| CVE-2026-86667 | aircheng-org iWebShop-5 member.php member_list sql injection | iWebShop-5 | 2.0 (v4.0) | Low |
| CVE-2026-38626 | Garlic-Hub v1.0.1 SQL Injection Vulnerability | - | N/A | N/A |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 341145
- Source revision: 4307
- Source revision date: 2013-12-02