On this page
Atomicorp WAF Rule 380026
Rule Summary
- Rule ID: 380026
- Status: Active
- Alert message: Atomicorp.com WAF Rules: PHP payload detected
- Observed CWEs: CWE-20 (2), CWE-22 (3), CWE-74 (258), CWE-77 (2), CWE-78 (1), CWE-79 (8), CWE-89 (638), CWE-94 (14), CWE-158 (1), CWE-184 (1), CWE-200 (4), CWE-266 (1), CWE-284 (3), CWE-285 (1), CWE-287 (3), CWE-288 (2), CWE-306 (1), CWE-434 (2), CWE-502 (2), CWE-697 (1), CWE-862 (2), CWE-863 (1), CWE-913 (2), CWE-917 (1), CWE-918 (1), CWE-1188 (1)
- Revision: 28
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request filename, Request cookies, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
- Rule action: deny
- HTTP status: 403
- Public tags: RCE, SQLi
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “PHP payload detected” in the request filename, request cookies, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2022-24816 | GeoServer <1.2.2 - Remote Code Execution | jai-ext | 10.0 (v3.1) | Critical |
| CVE-2025-47812 | Wing FTP Server <= 7.4.3 - Remote Code Execution | wftpserver | 10.0 (v3.1) | Critical |
| CVE-2025-55182 | React Server Components - Remote Code Execution | react | 10.0 (v3.1) | Critical |
| CVE-2025-59528 | Flowise - Remote Code Execution | flowise | 10.0 (v3.1) | Critical |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | dbgate | 10.0 (v3.1) | Critical |
| CVE-2026-53753 | Crawl4AI <= 0.8.6 - Remote Code Execution | crawl4ai | 10.0 (v3.1) | Critical |
| CVE-2026-72899 | Metabase SQL injection via public card or dashboard | Metabase | 10.0 (v4.0) | Critical |
| CVE-2019-10758 | mongo-express Remote Code Execution | mongo-express | 9.9 (v3.1) | Critical |
| CVE-2024-51482 | ZoneMinder v1.37.* <= 1.37.64 - SQL Injection | zoneminder | 9.9 (v3.1) | Critical |
| CVE-2026-51366 | Bottinelli Informatica Vedo Suite v.1.2.5 Arbitrary Code Execution Vulnerability | Bottinelli Informatica Vedo Suite v.1.2.5 | 9.9 (v3.1) | Critical |
| CVE-2026-69083 | SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent | siyuan | 9.9 (v4.0) | Critical |
| CVE-2026-69084 | SiYuan - SQL Execution | siyuan | 9.9 (v4.0) | Critical |
| CVE-2026-69085 | SiYuan before v3.7.3 SQL Injection via searchDocs | siyuan | 9.9 (v4.0) | Critical |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 9.8 (v3.0) | Critical |
| CVE-2015-1427 | ElasticSearch - Remote Code Execution | elasticsearch | 9.8 (v3.1) | Critical |
| CVE-2015-3933 | GeniXCMS 0.0.3 - 'register.php' SQL Injection | genixcms | 9.8 (v3.0) | Critical |
| CVE-2015-3934 | Fiyo CMS 2.0_1.9.1 - SQL Injection | fiyo cms | 9.8 (v3.0) | Critical |
| CVE-2016-2386 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | netweaver application server java | 9.8 (v3.1) | Critical |
| CVE-2017-17970 | Muviko 1.1 - SQL Injection | muviko | 9.8 (v3.0) | Critical |
| CVE-2017-17999 | RISE 1.9 - 'search' SQL Injection | rise ultimate project manager | 9.8 (v3.0) | Critical |
| CVE-2018-11511 | ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection | asustor data master | 9.8 (v3.0) | Critical |
| CVE-2018-11535 | Sitemakin SLAC 1.0 - 'my_item_search' SQL Injection | slac | 9.8 (v3.0) | Critical |
| CVE-2018-16763 | FUEL CMS 1.4.1 - Remote Code Execution | fuel cms | 9.8 (v3.1) | Critical |
| CVE-2018-18755 | K-iwi Framework 1775 - SQL Injection | k-iwi | 9.8 (v3.1) | Critical |
| CVE-2018-18761 | SaltOS Erp Crm 3.1 r8126 - SQL Injection | saltos | 9.8 (v3.1) | Critical |
| CVE-2018-18763 | SaltOS Erp Crm 3.1 r8126 - SQL Injection (2) | saltos | 9.8 (v3.0) | Critical |
| CVE-2018-3810 | Oturia WordPress Smart Google Code Inserter <3.5 - Authentication Bypass | smart google code inserter | 9.8 (v3.0) | Critical |
| CVE-2018-7538 | Tuleap 9.17.99.189 - Blind SQL Injection | tuleap | 9.8 (v3.0) | Critical |
| CVE-2019-7139 | Magento - SQL Injection | magento | 9.8 (v3.0) | Critical |
| CVE-2019-7194 | QNAP Photo Station < 6.0.3 - Remote Code Execution | photo station | 9.8 (v3.1) | Critical |
| CVE-2020-11530 | WordPress Chop Slider 3 - Blind SQL Injection | chop slider | 9.8 (v3.1) | Critical |
| CVE-2020-13640 | wpDiscuz <= 5.3.5 - SQL Injection | wpdiscuz | 9.8 (v3.1) | Critical |
| CVE-2020-14750 | Oracle WebLogic Server - Remote Command Execution | fusion middleware | 9.8 (v3.1) | Critical |
| CVE-2020-17463 | Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated) | fuel cms | 9.8 (v3.1) | Critical |
| CVE-2020-24391 | Mongo-Express - Remote Code Execution | mongo-express | 9.8 (v3.1) | Critical |
| CVE-2020-27615 | WordPress Loginizer < 1.6.4 – Unauthenticated SQL Injection via log Parameter | loginizer | 9.8 (v3.1) | Critical |
| CVE-2020-35545 | Spotweb 1.4.9 - 'search' SQL Injection | spotweb | 9.8 (v3.1) | Critical |
| CVE-2020-8656 | EyesOfNetwork - Hardcoded API Key & SQL Injection | eyesofnetwork | 9.8 (v3.1) | Critical |
| CVE-2021-24139 | 10Web Photo Gallery < 1.5.55 - SQL Injection | photo gallery | 9.8 (v3.1) | Critical |
| CVE-2021-24731 | Pie Register < 3.7.1.6 - SQL Injection | pie register | 9.8 (v3.1) | Critical |
| CVE-2021-24827 | WordPress Asgaros Forum <1.15.13 - SQL Injection | asgaros forum | 9.8 (v3.1) | Critical |
| CVE-2021-25114 | WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injection | paid memberships pro | 9.8 (v3.1) | Critical |
| CVE-2021-26599 | ImpressCMS < 1.4.3 - SQL Injection | impresscms | 9.8 (v3.1) | Critical |
| CVE-2021-27314 | Doctor Appointment System 1.0 - SQL Injection | doctor appointment system | 9.8 (v3.1) | Critical |
| CVE-2021-3110 | PrestaShop 1.7.7.0 - SQL Injection | prestashop | 9.8 (v3.1) | Critical |
| CVE-2022-0332 | Moodle 3.11.4 - SQL Injection | moodle | 9.8 (v3.1) | Critical |
| CVE-2022-0349 | WordPress NotificationX <2.3.9 - SQL Injection | notificationx | 9.8 (v3.1) | Critical |
| CVE-2022-0412 | WordPress TI WooCommerce Wishlist <1.40.1 - SQL Injection | ti woocommerce wishlist | 9.8 (v3.1) | Critical |
| CVE-2022-0592 | MapSVG < 6.2.20 - Unauthenticated SQLi | mapsvg | 9.8 (v3.1) | Critical |
| CVE-2022-0788 | WordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL Injection | wp fundraising donation and crowdfunding platform | 9.8 (v3.1) | Critical |
| CVE-2022-0948 | WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection | order listener for woocommerce | 9.8 (v3.1) | Critical |
| CVE-2022-22897 | PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injection | ap pagebuilder | 9.8 (v3.1) | Critical |
| CVE-2022-2467 | Garage Management System 1.0 - SQL Injection | garage management system | 9.8 (v3.1) | Critical |
| CVE-2022-27927 | Microfinance Management System 1.0 - 'customer_number' SQLi | microfinance management system | 9.8 (v3.1) | Critical |
| CVE-2022-27984 | Cuppa CMS v1.0 - SQL injection | cuppacms | 9.8 (v3.1) | Critical |
| CVE-2022-28032 | Atom CMS v2.0 - SQL Injection | atomcms | 9.8 (v3.1) | Critical |
| CVE-2022-28033 | Atom.CMS 2.0 - SQL Injection | atomcms | 9.8 (v3.1) | Critical |
| CVE-2022-29078 | Node.js Embedded JavaScript 3.1.6 - Template Injection | ejs | 9.8 (v3.1) | Critical |
| CVE-2022-31340 | simple inventory system SQL Injection Vulnerability | simple inventory system | 9.8 (v3.1) | Critical |
| CVE-2022-31976 | Online Fire Reporting System v1.0 - SQL injection | online fire reporting system | 9.8 (v3.1) | Critical |
| CVE-2022-31977 | Online Fire Reporting System v1.0 - SQL injection | online fire reporting system | 9.8 (v3.1) | Critical |
| CVE-2022-31978 | Online Fire Reporting System v1.0 - SQL injection | online fire reporting system | 9.8 (v3.1) | Critical |
| CVE-2022-33965 | WordPress Visitor Statistics <=5.7 - SQL Injection | wp visitor statistics | 9.8 (v3.1) | Critical |
| CVE-2022-3481 | NotificationX Dropshipping < 4.4 - SQL Injection | woocommerce dropshipping | 9.8 (v3.1) | Critical |
| CVE-2022-40032 | Simple Task Managing System v1.0 - SQL Injection (Unauthenticated) | simple task managing system | 9.8 (v3.1) | Critical |
| CVE-2022-40347 | Intern Record System v1.0 - SQL Injection (Unauthenticated) | intern record system | 9.8 (v3.1) | Critical |
| CVE-2022-44290 | WebTareas 2.4p5 - SQL Injection | webtareas | 9.8 (v3.1) | Critical |
| CVE-2022-44291 | WebTareas 2.4p5 - SQL Injection | webtareas | 9.8 (v3.1) | Critical |
| CVE-2022-45808 | LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLi | learnpress | 9.8 (v3.1) | Critical |
| CVE-2023-0037 | WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injection | map builder for google maps | 9.8 (v3.1) | Critical |
| CVE-2023-0600 | WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL Injection | wp visitor statistics | 9.8 (v3.1) | Critical |
| CVE-2023-1730 | SupportCandy < 3.1.5 - Unauthenticated SQL Injection | supportcandy | 9.8 (v3.1) | Critical |
| CVE-2023-2130 | Purchase Order Management v1.0 - SQL Injection | purchase order management system | 9.8 (v3.1) | Critical |
| CVE-2023-24000 | WordPress GamiPress <= 2.5.7 - SQL Injection | gamipress | 9.8 (v3.1) | Critical |
| CVE-2023-27637 | PrestaShop tshirtecommerce Module - SQL Injection | custom product designer | 9.8 (v3.1) | Critical |
| CVE-2023-27638 | tshirtecommerce PrestaShop Module - SQL Injection | prestashop | 9.8 (v3.1) | Critical |
| CVE-2023-27847 | PrestaShop xipblog - SQL Injection | xipblog | 9.8 (v3.1) | Critical |
| CVE-2023-29827 | Embedded JavaScript(EJS) 3.1.6 - Template Injection | ejs | 9.8 (v3.1) | Critical |
| CVE-2023-30150 | PrestaShop leocustomajax 1.0 & 1.0.0 - SQL Injection | leocustomajax | 9.8 (v3.1) | Critical |
| CVE-2023-30192 | PrestaShop 'possearchproducts' <= 1.7 - SQL Injection | possearchproducts | 9.8 (v3.1) | Critical |
| CVE-2023-3077 | MStore API < 3.9.8 - SQL Injection | mstore api | 9.8 (v3.1) | Critical |
| CVE-2023-3197 | WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection | mstore api | 9.8 (v3.1) | Critical |
| CVE-2023-33831 | FUXA - Unauthenticated Remote Code Execution | fuxa | 9.8 (v3.1) | Critical |
| CVE-2023-34751 | bloofoxCMS v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 (v3.1) | Critical |
| CVE-2023-34752 | bloofoxCMS v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 (v3.1) | Critical |
| CVE-2023-34753 | bloofoxCMS v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 (v3.1) | Critical |
| CVE-2023-34754 | Bloofox v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 (v3.1) | Critical |
| CVE-2023-34755 | bloofoxCMS v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 (v3.1) | Critical |
| CVE-2023-34756 | Bloofox v0.5.2.1 - SQL Injection | bloofoxcms | 9.8 (v3.1) | Critical |
| CVE-2023-39361 | Cacti 1.2.24 - SQL Injection | cacti | 9.8 (v3.1) | Critical |
| CVE-2023-39650 | PrestaShop Theme Volty CMS Blog - SQL Injection | theme volty cms blog | 9.8 (v3.1) | Critical |
| CVE-2023-39796 | WBCE 1.6.0 - Unauthenticated SQL injection | wbce cms | 9.8 (v3.1) | Critical |
| CVE-2023-43373 | Hoteldruid v3.0.5 - SQL Injection | hoteldruid | 9.8 (v3.1) | Critical |
| CVE-2023-43374 | Hoteldruid v3.0.5 - SQL Injection | hoteldruid | 9.8 (v3.1) | Critical |
| CVE-2023-4490 | WordPress Job Portal < 2.0.6 - SQL Injection | wp job portal | 9.8 (v3.1) | Critical |
| CVE-2023-48084 | Nagios XI < 5.11.3 - SQL Injection | nagios xi | 9.8 (v3.1) | Critical |
| CVE-2023-4974 | Academy LMS 6.2 - SQL Injection | academy lms | 9.8 (v3.1) | Critical |
| CVE-2023-6360 | WordPress My Calendar <3.4.22 - SQL Injection | my calendar | 9.8 (v3.1) | Critical |
| CVE-2024-1061 | WordPress HTML5 Video Player - SQL Injection | html5 video player | 9.8 (v3.1) | Critical |
| CVE-2024-1512 | MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection | masterstudy lms | 9.8 (v3.1) | Critical |
| CVE-2024-1698 | NotificationX <= 2.8.2 - SQL Injection | notificationx | 9.8 (v3.1) | Critical |
| CVE-2024-24495 | Daily Habit Tracker 1.0 - SQL Injection | daily habit tracker | 9.8 (v3.1) | Critical |
| CVE-2024-2621 | Fujian Kelixin Communication - Command Injection | kelixin communication command and dispatch | 9.8 (v3.1) | Critical |
| CVE-2024-27348 | Apache HugeGraph-Server - Remote Command Execution | hugegraph | 9.8 (v3.1) | Critical |
| CVE-2024-27956 | WordPress Automatic Plugin <= 3.92.0 - SQL Injection | automatic | 9.8 (v3.1) | Critical |
| CVE-2024-2876 | Wordpress Email Subscribers by Icegram Express - SQL Injection | Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | 9.8 (v3.1) | Critical |
| CVE-2024-30163 | IPS Community Suite - Unauthenticated SQL Injection | ips community suite | 9.8 (v3.1) | Critical |
| CVE-2024-30502 | WP Travel Engine <= 5.7.9 - SQL Injection | wp travel engine | 9.8 (v3.1) | Critical |
| CVE-2024-3605 | WP Hotel Booking <= 2.1.0 - SQL Injection | wp hotel booking | 9.8 (v3.1) | Critical |
| CVE-2024-36412 | SuiteCRM - SQL Injection | suitecrm | 9.8 (v3.1) | Critical |
| CVE-2024-39907 | 1Panel SQL Injection - Authenticated | 1panel | 9.8 (v3.1) | Critical |
| CVE-2024-43360 | ZoneMinder - SQL Injection | zoneminder | 9.8 (v3.1) | Critical |
| CVE-2024-43917 | WordPress TI WooCommerce Wishlist Plugin <= 2.8.2 - SQL Injection | ti woocommerce wishlist | 9.8 (v3.1) | Critical |
| CVE-2024-6205 | PayPlus Payment Gateway < 6.6.9 - SQL Injection | payplus payment gateway | 9.8 (v3.1) | Critical |
| CVE-2024-6265 | UsersWP <= 1.2.10 - Unauthenticated SQL Injection | userswp | 9.8 (v3.1) | Critical |
| CVE-2024-7314 | AJ-Report < 1.4.1 - Remote Code Execution | report | 9.8 (v3.1) | Critical |
| CVE-2025-24799 | GLPI < 10.0.17 - Pre-Auth SQL Injection | glpi | 9.8 (v3.1) | Critical |
| CVE-2025-32814 | NetMRI Unauthenticated SQL Injection via skipjackUsername | netmri | 9.8 (v3.1) | Critical |
| CVE-2025-57631 | tduck Arbitrary Code Execution Vulnerability | tduck | 9.8 (v3.1) | Critical |
| CVE-2025-65336 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-65340 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-67066 | oasys sysoa version 1.0 Arbitrary Code Execution Vulnerability | oasys sysoa version 1.0 | 9.8 (v3.1) | Critical |
| CVE-2025-67403 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-67404 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69930 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69931 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69933 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69934 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69935 | SQL Injection | - | 9.8 (v3.1) | Critical |
| CVE-2025-69936 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69937 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69938 | CodeAstro Membership Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69941 | SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69942 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69943 | SQL Injection | - | 9.8 (v3.1) | Critical |
| CVE-2025-69946 | SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69947 | SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-69948 | SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2025-70149 | membership management system SQL Injection Vulnerability | membership management system | 9.8 (v3.1) | Critical |
| CVE-2025-70150 | membership management system Missing Authorization Vulnerability | membership management system | 9.8 (v3.1) | Critical |
| CVE-2025-70152 | scholars tracking system SQL Injection Vulnerability | scholars tracking system | 9.8 (v3.1) | Critical |
| CVE-2026-10880 | Unauthenticated SQL Injection in Osnexus Quantastor | QuantaStor | 9.8 (v3.1) | Critical |
| CVE-2026-46670 | YesWiki: Unauthenticated SQL Injection | yeswiki | 9.8 (v3.1) | Critical |
| CVE-2026-48528 | Metacat has an unauthenticated SQL injection vulnerability | metacat | 9.8 (v3.1) | Critical |
| CVE-2026-51775 | Fastadmin v.1.6.1.20250430 SQL Injection Vulnerability | Fastadmin v.1.6.1.20250430 | 9.8 (v3.1) | Critical |
| CVE-2026-52348 | cool-admin-java 8.0.0 SQL Injection Vulnerability | cool-admin-java 8.0.0 | 9.8 (v3.1) | Critical |
| CVE-2026-52472 | Wgcloud 3.6.4 SQL Injection Vulnerability | Wgcloud 3.6.4 | 9.8 (v3.1) | Critical |
| CVE-2026-67689 | FineAdmin V1.0 Arbitrary Code Execution Vulnerability | FineAdmin V1.0 | 9.8 (v3.1) | Critical |
| CVE-2026-68000 | MCMS <=6.2.0 is vulnerable to SQL injection Vulnerability | MCMS <=6.2.0 is vulnerable to SQL injection | 9.8 (v3.1) | Critical |
| CVE-2026-69240 | Sequelize: SQL Injection (Oracle DB) | sequelize | 9.8 (v3.1) | Critical |
| CVE-2026-75330 | super-diamond-server <= 1.3.3 is vulnerable to SQL injection Vulnerability | super-diamond-server <= 1.3.3 is vulnerable to SQL injection | 9.8 (v3.1) | Critical |
| CVE-2026-77806 | SPIP < 4.4.22 - Unauthenticated RCE | SPIP | 9.8 (v3.1) | Critical |
| CVE-2026-79569 | Movie_Recommend v1.0.0 SQL Injection Vulnerability | Movie Recommend v1.0.0 | 9.8 (v3.1) | Critical |
| CVE-2026-79570 | mfish-nocode-pro v1.0.0 SQL Injection Vulnerability | mfish-nocode-pro v1.0.0 | 9.8 (v3.1) | Critical |
| CVE-2026-6875 | ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE | servicenow | 9.5 (v4.0) | Critical |
| CVE-2019-16383 | MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection | moveit transfer | 9.4 (v3.1) | Critical |
| CVE-2026-39342 | ChurchCRM has a SQL injection searchwhat parameter via QueryView.php | churchcrm | 9.4 (v4.0) | Critical |
| CVE-2026-44262 | Scramble Laravel - Remote Code Execution | scramble | 9.4 (v3.1) | Critical |
| CVE-2026-47670 | DbGate - Remote Code Execution via Dynamic Import Bypass | dbgate | 9.4 (v4.0) | Critical |
| CVE-2016-20096 | Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp | Linknat VOS3000 | 9.3 (v4.0) | Critical |
| CVE-2023-28787 | Quiz and Survey Master <= 8.1.4 - SQL Injection | Quiz And Survey Master | 9.3 (v3.1) | Critical |
| CVE-2024-32128 | WordPress Realtyna Organic IDX Plugin <= 4.14.4 - SQL Injection | Realtyna Organic IDX plugin | 9.3 (v3.1) | Critical |
| CVE-2025-1023 | ChurchCRM - SQL Injection | churchcrm | 9.3 (v4.0) | Critical |
| CVE-2025-32969 | XWiki REST API Query - SQL Injection | xwiki | 9.3 (v4.0) | Critical |
| CVE-2025-48281 | MyStyle Custom Product Designer <= 3.21.1 - SQL Injection | MyStyle Custom Product Designer | 9.3 (v3.1) | Critical |
| CVE-2025-54726 | WordPress JS Archive List <= 6.1.5 - SQL Injection | JS Archive List | 9.3 (v3.1) | Critical |
| CVE-2026-29014 | MetInfo CMS <= 8.1 - Remote Code Execution | metinfo | 9.3 (v4.0) | Critical |
| CVE-2026-40329 | SQL Injection vulnerability via sortBy in beanFeed | MasaCMS | 9.3 (v4.0) | Critical |
| CVE-2026-40330 | Masa CMS SQL injection via sortDirection parameter in beanFeed | MasaCMS | 9.3 (v4.0) | Critical |
| CVE-2026-54836 | YMC Filter - SQL Injection | YMC Filter | 9.3 (v3.1) | Critical |
| CVE-2026-58138 | Orkes Conductor 3.21.21-3.30.1 - Remote Code Execution | conductor | 9.3 (v4.0) | Critical |
| CVE-2026-63106 | ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php | Ready eCommerce | 9.3 (v4.0) | Critical |
| CVE-2026-65761 | Joomla Easy Store - SQL Injection | Easy Store | 9.3 (v4.0) | Critical |
| CVE-2026-81672 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 9.3 (v4.0) | Critical |
| CVE-2026-81673 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 9.3 (v4.0) | Critical |
| CVE-2026-81674 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 9.3 (v4.0) | Critical |
| CVE-2026-81675 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 9.3 (v4.0) | Critical |
| CVE-2026-82526 | R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint | R2R | 9.3 (v4.0) | Critical |
| CVE-2026-9586 | Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection | switchvox | 9.3 (v4.0) | Critical |
| CVE-2024-5217 | ServiceNow - Incomplete Input Validation | servicenow | 9.2 (v4.0) | Critical |
| CVE-2024-9465 | Palo Alto Expedition - SQL Injection | expedition | 9.2 (v4.0) | Critical |
| CVE-2021-37593 | PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection | peel shopping | 9.1 (v3.1) | Critical |
| CVE-2022-44727 | PrestaShop lgcookieslaw - SQL Injection | eu cookie law gdpr | 9.1 (v3.1) | Critical |
| CVE-2025-50455 | the CodeIgniter Query Builder Arbitrary Code Execution Vulnerability | the CodeIgniter Query Builder | 9.1 (v3.1) | Critical |
| CVE-2026-16532 | Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form | Link Library | 9.1 (v3.1) | Critical |
| CVE-2026-73069 | Twenty: SQL Injection in the searchVector Field Settings Allows Arbitrary PostgreSQL Execution | twenty | 9.1 (v3.1) | Critical |
| CVE-2025-1302 | JSONPath Plus < 10.3.0 - Remote Code Execution | jsonpath-plus | 8.9 (v4.0) | High |
| CVE-2017-20243 | WordPress Car Park Booking Plugin SQL Injection via space_id | Car Park Booking System | 8.8 (v4.0) | High |
| CVE-2017-20247 | WordPress Plugin PICA Photo Gallery 1.0 SQL Injection | PICA Photo Gallery | 8.8 (v4.0) | High |
| CVE-2017-20249 | WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection | Apptha Slider Gallery | 8.8 (v4.0) | High |
| CVE-2017-20260 | Joomla! Component Price Alert 3.0.2 SQL Injection | price alert | 8.8 (v4.0) | High |
| CVE-2017-20261 | Joomla! Component Bargain Product VM3 1.0 SQL Injection | bargain product vm3 | 8.8 (v4.0) | High |
| CVE-2017-20263 | Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via location | focalpoint | 8.8 (v4.0) | High |
| CVE-2017-20266 | Joomla SP Movie Database 1.3 SQL Injection via searchword | standard pro movie database | 8.8 (v4.0) | High |
| CVE-2017-20267 | Joomla! Component Calendar Planner 1.0.1 SQL Injection | calendar planner | 8.8 (v4.0) | High |
| CVE-2017-20268 | Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection | zap calendar lite | 8.8 (v4.0) | High |
| CVE-2017-20271 | Joomla StreetGuessr Game 1.1.8 SQL Injection via catid | streetguessr game | 8.8 (v4.0) | High |
| CVE-2017-20272 | Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id | ultimate property listing | 8.8 (v4.0) | High |
| CVE-2017-20273 | Joomla Event Registration Pro Calendar 4.1.3 SQL Injection | event registration pro calendar | 8.8 (v4.0) | High |
| CVE-2017-20274 | Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath | learning management system king | 8.8 (v4.0) | High |
| CVE-2017-20275 | Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter | bridge | 8.8 (v4.0) | High |
| CVE-2017-20276 | Joomla! Component SIMGenealogy 2.1.5 SQL Injection | simgenealogy | 8.8 (v4.0) | High |
| CVE-2017-20277 | Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author | joomla joomrecipe | 8.8 (v4.0) | High |
| CVE-2017-20278 | Joomla JoomRecipe 1.0.3 SQL Injection via category parameter | joomrecipe | 8.8 (v4.0) | High |
| CVE-2017-20279 | Joomla Payage 2.05 SQL Injection via aid Parameter | joomla payage | 8.8 (v4.0) | High |
| CVE-2017-20280 | Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter | myportfolio | 8.8 (v4.0) | High |
| CVE-2017-20281 | Joomla! Component Extra Search 2.2.8 SQL Injection | extra search | 8.8 (v4.0) | High |
| CVE-2017-20282 | Joomla! Component jCart for OpenCart 2.0 SQL Injection | jcart for opencart | 8.8 (v4.0) | High |
| CVE-2018-25340 | Smartshop 1 SQL Injection via category.php | Smartshop | 8.8 (v4.0) | High |
| CVE-2018-25341 | Smartshop 1 SQL Injection via product.php id Parameter | Smartshop | 8.8 (v4.0) | High |
| CVE-2018-25342 | Smartshop 1 SQL Injection via search.php | Smartshop | 8.8 (v4.0) | High |
| CVE-2018-25348 | Joomla! Component Ek Rishta 2.10 SQL Injection via user_detail | Ek Rishta | 8.8 (v4.0) | High |
| CVE-2018-25351 | Joomla! Component EkRishta 2.10 SQL Injection via username | EkRishta | 8.8 (v4.0) | High |
| CVE-2018-25362 | Twitter-Clone 1 SQL Injection via follow.php | PHP-Twitter-Clone | 8.8 (v4.0) | High |
| CVE-2018-25364 | Twitter-Clone 1 SQL Injection via search.php | PHP-Twitter-Clone | 8.8 (v4.0) | High |
| CVE-2018-25371 | mooSocial Store Plugin 2.6 SQL Injection via product parameter | mooSocial Store Plugin | 8.8 (v4.0) | High |
| CVE-2018-25385 | E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai | Registrasi Pencak Silat | 8.8 (v4.0) | High |
| CVE-2018-25386 | HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php | HaPe PKH | 8.8 (v4.0) | High |
| CVE-2018-25394 | Kados R10 GreenBee SQL Injection via update_release.php | Kados R10 GreenBee | 8.8 (v4.0) | High |
| CVE-2018-25395 | Kados R10 GreenBee SQL Injection via update_feature.php | Kados R10 GreenBee | 8.8 (v4.0) | High |
| CVE-2018-25411 | MGB OpenSource Guestbook 0.7.0.2 SQL Injection via email.php | MGB OpenSource Guestbook | 8.8 (v4.0) | High |
| CVE-2018-25413 | AiOPMSD Final 1.0.0 SQL Injection via search.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25414 | AiOPMSD Final 1.0.0 SQL Injection via actor.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25416 | AiOPMSD Final 1.0.0 SQL Injection via country.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25417 | AiOPMSD Final 1.0.0 SQL Injection via quality.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25418 | AiOPMSD Final 1.0.0 SQL Injection via year.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25419 | AiOPMSD Final 1.0.0 SQL Injection via genre.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25420 | AiOPMSD Final 1.0.0 SQL Injection via watch.php | AiOPMSD Final | 8.8 (v4.0) | High |
| CVE-2018-25422 | MOGG web simulator Script All Version SQL Injection via play.php | MOGG web simulator Script | 8.8 (v4.0) | High |
| CVE-2018-25424 | Gate Pass Management System 2.1 SQL Injection via login-exec.php | Gate Pass Management System | 8.8 (v4.0) | High |
| CVE-2018-25425 | Yot CMS 3.3.1 SQL Injection via aid and cid Parameters | Yot CMS | 8.8 (v4.0) | High |
| CVE-2018-25428 | Paroiciel 11.20 SQL Injection via tRecIdListe Parameter | Paroiciel | 8.8 (v4.0) | High |
| CVE-2018-25433 | Joomla JE Photo Gallery 1.1 SQL Injection via categoryid | JE Photo Gallery | 8.8 (v4.0) | High |
| CVE-2018-25434 | WP AutoSuggest 0.24 SQL Injection via autosuggest.php | WP AutoSuggest | 8.8 (v4.0) | High |
| CVE-2019-25662 | ResourceSpace 8.6 SQL Injection via watched_searches.php | resourcespace | 8.8 (v4.0) | High |
| CVE-2019-25668 | News Website Script 2.0.5 SQL Injection via index.php | news website script | 8.8 (v4.0) | High |
| CVE-2019-25669 | qdPM 9.1 SQL Injection via search_by_extrafields Parameter | qdpm | 8.8 (v4.0) | High |
| CVE-2019-25675 | eDirectory All Versions SQL Injection Authentication Bypass | edirectory | 8.8 (v4.0) | High |
| CVE-2019-25678 | C4G BLIS 3.4 SQL Injection via users_select.php | computing for good's basic laboratory information system | 8.8 (v4.0) | High |
| CVE-2019-25680 | Advance Gift Shop Pro Script 2.0.3 SQL Injection via search | advance gift shop pro script | 8.8 (v4.0) | High |
| CVE-2019-25684 | OpenDocMan 1.3.4 SQL Injection via where Parameter | opendocman | 8.8 (v4.0) | High |
| CVE-2019-25694 | Kados R10 GreenBee SQL Injection via user2reset | kados | 8.8 (v4.0) | High |
| CVE-2019-25728 | Care2x 2.7 Hospital Information System SQL Injection via ck_config | Care2x | 8.8 (v4.0) | High |
| CVE-2019-25730 | Listing Hub CMS 1.0 SQL Injection via pages.php id | Listing Hub CMS | 8.8 (v4.0) | High |
| CVE-2019-25732 | PHP EI-Tube Script 3 SQL Injection via search parameter | EI-Tube | 8.8 (v4.0) | High |
| CVE-2019-25745 | WordPress Plugin Google Review Slider 6.1 SQL Injection via tid | Google Review Slider | 8.8 (v4.0) | High |
| CVE-2019-25748 | Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels | jhotelreservation | 8.8 (v4.0) | High |
| CVE-2019-25750 | Joomla J-MultipleHotelReservation 6.0.7 SQL Injection | multiplehotelreservation | 8.8 (v4.0) | High |
| CVE-2019-25751 | Joomla J-ClassifiedsManager 3.0.5 SQL Injection | classifiedsmanager | 8.8 (v4.0) | High |
| CVE-2019-25752 | Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection | j-businessdirectory | 8.8 (v4.0) | High |
| CVE-2019-25756 | Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard | vaccount | 8.8 (v4.0) | High |
| CVE-2020-15876 | SQL Injection | - | 8.8 (v3.1) | High |
| CVE-2020-15878 | SQL Injection | - | 8.8 (v3.1) | High |
| CVE-2020-6010 | WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated) | learnpress | 8.8 (v3.1) | High |
| CVE-2021-25646 | Apache Druid - Remote Code Execution | druid | 8.8 (v3.1) | High |
| CVE-2021-32819 | Nodejs Squirrelly - Remote Code Execution | squirrelly | 8.8 (v3.1) | High |
| CVE-2021-47928 | Opencart TMD Vendor System 3.x Blind SQL Injection via product route | Extension TMD Vendor System | 8.8 (v4.0) | High |
| CVE-2021-47930 | Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated | Balbooa Joomla Forms Builder | 8.8 (v4.0) | High |
| CVE-2022-3768 | WordPress WPSmartContracts <1.3.12 - SQL Injection | wpsmartcontracts | 8.8 (v3.1) | High |
| CVE-2023-7137 | Client Details System 1.0 - SQL Injection | client details system | 8.8 (v3.1) | High |
| CVE-2025-45868 | LogicalDOC Enterprise up to and for v9.1.1 SQL Injection Vulnerability | - | 8.8 (v3.1) | High |
| CVE-2025-68613 | n8n - Remote Code Execution via Expression Injection | n8n | 8.8 (v3.1) | High |
| CVE-2026-31069 | BillaBear (all versions prior to Jan 2026) SQL Injection Vulnerability | BillaBear (all versions prior to Jan 2026) | 8.8 (v3.1) | High |
| CVE-2026-35395 | WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameter | wegia | 8.8 (v3.1) | High |
| CVE-2026-35470 | OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals | openstamanager | 8.8 (v3.1) | High |
| CVE-2026-41075 | RT: SQL injection via entry_aggregator parameter in JSON search | rt | 8.8 (v3.1) | High |
| CVE-2026-44741 | Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parame | pimcore | 8.8 (v3.1) | High |
| CVE-2026-52775 | YesWiki Authenticated SQL Injection in ReactionManager | yeswiki | 8.8 (v3.1) | High |
| CVE-2026-53629 | GLPI - Blind SQL Injection in History Log Filter (LogBleed) | - | 8.8 (v3.1) | High |
| CVE-2026-55084 | SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read | dhis2-core | 8.8 (v3.1) | High |
| CVE-2026-55509 | WsgiDAV: Blind SQL injection in the MySQL provider | wsgidav | 8.8 (v4.0) | High |
| CVE-2026-70369 | Koha - SQL Injection in reports/acquisitions_stats.pl | Koha | 8.8 (v3.1) | High |
| CVE-2026-70370 | Koha - SQL Injection in reports/catalogue_stats.pl | Koha | 8.8 (v3.1) | High |
| CVE-2026-70373 | Koha - SQL Injection in reports/issues_stats.pl | Koha | 8.8 (v3.1) | High |
| CVE-2026-81676 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 8.8 (v4.0) | High |
| CVE-2026-81677 | Multiple Vulnerabilities in TOOOLS' iSquad | iSquad | 8.8 (v4.0) | High |
| CVE-2016-20097 | Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad | E-cology 8.0 | 8.7 (v4.0) | High |
| CVE-2019-25765 | ASP-CMS SQL Injection via commentList.asp id Parameter | ASP-CMS | 8.7 (v4.0) | High |
| CVE-2022-50997 | Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp | E-cology 9.0 | 8.7 (v4.0) | High |
| CVE-2024-58374 | Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree | e-HR | 8.7 (v4.0) | High |
| CVE-2026-23921 | Blind, read-only SQL injection in Zabbix API via sortfield parameter | zabbix | 8.7 (v4.0) | High |
| CVE-2026-27634 | Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter | piwigo | 8.7 (v4.0) | High |
| CVE-2026-31844 | Authenticated SQL Injection in Koha displayby parameter of suggestion.pl | koha | 8.7 (v4.0) | High |
| CVE-2026-34100 | Guardian Language-System SQL Injection via id Parameter in media.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34101 | Guardian Language-System SQL Injection via id Parameter in text_file.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34102 | Guardian Language-System SQL Injection via id Parameter in job_info_get.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34103 | Guardian Language-System SQL Injection via id Parameter in subtitles.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34104 | Guardian Language-System SQL Injection via name Parameter in designer.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-34105 | Guardian Language-System SQL Injection via id Parameter in translate_text.php | language-system | 8.7 (v4.0) | High |
| CVE-2026-35184 | EcclesiaCRM has a Critical SQL Injection | ecclesiacrm | 8.7 (v4.0) | High |
| CVE-2026-41453 | Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter | laravel-crm | 8.7 (v4.0) | High |
| CVE-2026-44739 | Pimcore: SQL Injection in Custom Reports Column Configuration | pimcore | 8.7 (v3.1) | High |
| CVE-2026-44886 | Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection | Pi.Alert | 8.7 (v4.0) | High |
| CVE-2026-50636 | LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection | LimeSurvey | 8.7 (v4.0) | High |
| CVE-2026-61518 | ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter | ispconfig3 | 8.7 (v4.0) | High |
| CVE-2026-72708 | SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter | SPIP | 8.7 (v4.0) | High |
| CVE-2026-82527 | R2R 3.6.6 SQL Injection via Retrieval Search Filter Key | R2R | 8.7 (v4.0) | High |
| CVE-2026-82655 | Admidio before 5.0.12 SQL Injection via relation_type_list | admidio | 8.7 (v4.0) | High |
| CVE-2026-84208 | AVideo User_Location Plugin Unauthenticated SQL Injection | AVideo | 8.7 (v4.0) | High |
| CVE-2026-85155 | WWBN AVideo SQL Injection via get.json.php APIName channels | AVideo | 8.7 (v4.0) | High |
| CVE-2026-87807 | siyuan before v3.8.2 SQL Injection via fullTextSearchBlock | siyuan | 8.7 (v4.0) | High |
| CVE-2024-13726 | Themes Coder Ecommerce <= 1.3.4 - SQL Injection | tc-ecommerce | 8.6 (v3.1) | High |
| CVE-2024-9186 | Automation By Autonami < 3.3.0 - SQL Injection | wp-marketing-automations | 8.6 (v3.1) | High |
| CVE-2026-12721 | Kirki < 6.0.13 - Unauthenticated SQL Injection | Kirki | 8.6 (v3.1) | High |
| CVE-2026-16061 | Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name} | Rest Routes | 8.6 (v3.1) | High |
| CVE-2026-3326 | XStore Theme < 9.7.3 - SQL Injection | Xstore | 8.6 (v3.1) | High |
| CVE-2026-39931 | OpenEMR Authenticated SQL Injection via backup.php Import Feature | openemr | 8.6 (v4.0) | High |
| CVE-2026-42425 | OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery | OpenKM Community Edition | 8.6 (v4.0) | High |
| CVE-2026-73670 | CMS Admin SQL Injection via db_data.php table_name Parameter | Saurus CMS Community Edition | 8.6 (v4.0) | High |
| CVE-2026-73850 | Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Function | emlog | 8.6 (v4.0) | High |
| CVE-2026-76205 | phpMyFAQ before 4.1.7 SQL Injection via Glossary | phpmyfaq | 8.6 (v4.0) | High |
| CVE-2026-76635 | baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php | basercms | 8.6 (v4.0) | High |
| CVE-2026-79322 | mageplaza blog SQL Injection Vulnerability | mageplaza blog | 8.6 (v3.1) | High |
| CVE-2026-81728 | Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys | dolibarr erp/crm | 8.6 (v4.0) | High |
| CVE-2026-44238 | FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports | freepbx | 8.5 (v4.0) | High |
| CVE-2026-44706 | Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values | chatwoot | 8.5 (v3.1) | High |
| CVE-2026-65707 | Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint | likeshop | 8.5 (v4.0) | High |
| CVE-2026-49489 | OpenCATS - SQL Injection in DataGrid sortDirection Parameter | OpenCATS | 8.4 (v4.0) | High |
| CVE-2026-64657 | Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL | budibase | 8.4 (v3.1) | High |
| CVE-2026-88890 | OpenPanel SQL Injection via unvalidated profile filter column identifier | openpanel | 8.4 (v4.0) | High |
| CVE-2026-52771 | YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (ApiController::deletePage) | yeswiki | 8.3 (v3.1) | High |
| CVE-2020-26248 | PrestaShop Product Comments <4.2.0 - SQL Injection | productcomments | 8.2 (v3.1) | High |
| CVE-2026-14920 | AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter | AcyMailing | 8.2 (v3.1) | High |
| CVE-2014-3120 | ElasticSearch v1.1.1/1.2 RCE | elasticsearch | 8.1 (v3.1) | High |
| CVE-2017-12615 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | 8.1 (v3.1) | High |
| CVE-2026-15258 | Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter | Product Feed Manager For WooCommerce | 8.1 (v3.1) | High |
| CVE-2026-39341 | SQL injection in ChurchCRM.0 | churchcrm | 8.1 (v3.1) | High |
| CVE-2024-32136 | BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL Injection | BWL Advanced FAQ Manager | 7.6 (v3.1) | High |
| CVE-2014-8682 | Gogs (Go Git Service) - SQL Injection | gogs | 7.5 (v2.0) | High |
| CVE-2014-9145 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v2.0) | High |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v3.0) | High |
| CVE-2014-9215 | PBBoard CMS 3.0.1 - SQL Injection | pbboard | 7.5 (v2.0) | High |
| CVE-2015-1518 | RedaxScript CMS 2.2.0 - SQL Injection | redaxscript | 7.5 (v2.0) | High |
| CVE-2015-2824 | WordPress Plugin Simple Ads Manager - Multiple SQL Injections | simple ads manager | 7.5 (v2.0) | High |
| CVE-2020-22165 | PHPGurukul Hospital Management System 4.0 - SQL Injection | hospital management system | 7.5 (v3.1) | High |
| CVE-2021-25899 | Void Aural Rec Monitor 9.0.0.1 - SQL Injection | aurall rec monitor | 7.5 (v3.1) | High |
| CVE-2021-27316 | Doctor Appointment System 1.0 - SQL Injection | doctor appointment system | 7.5 (v3.1) | High |
| CVE-2021-27320 | Doctor Appointment System 1.0 - SQL Injection | doctor appointment system | 7.5 (v3.1) | High |
| CVE-2022-1453 | RSVPMaker <= 9.2.5 - SQL Injection | rsvpmaker | 7.5 (v3.1) | High |
| CVE-2022-1768 | WordPress RSVPMaker <=9.3.2 - SQL Injection | rsvpmaker | 7.5 (v3.1) | High |
| CVE-2022-24265 | Cuppa CMS v1.0 - SQL injection | cuppacms | 7.5 (v3.1) | High |
| CVE-2022-24266 | Cuppa CMS v1.0 - SQL injection | cuppacms | 7.5 (v3.1) | High |
| CVE-2023-32590 | Subscribe to Category <= 2.7.4 - SQL Injection | subscribe to category | 7.5 (v3.1) | High |
| CVE-2023-36284 | QloApps 1.6.0 - SQL Injection | qloapps | 7.5 (v3.1) | High |
| CVE-2023-5203 | WP Sessions Time Monitoring Full Automatic <= 1.0.8 - SQL Injection | wp sessions time monitoring full automatic | 7.5 (v3.1) | High |
| CVE-2023-6063 | WP Fastest Cache 1.2.2 - Unauthenticated SQL Injection | wp fastest cache | 7.5 (v3.1) | High |
| CVE-2023-6567 | LearnPress <= 4.2.5.7 - SQL Injection | learnpress | 7.5 (v3.1) | High |
| CVE-2024-12025 | WordPress Collapsing Categories <= 3.0.8 - SQL Injection | Collapsing Categories | 7.5 (v3.1) | High |
| CVE-2024-4443 | Business Directory Plugin <= 6.4.2 - SQL Injection | business directory | 7.5 (v3.1) | High |
| CVE-2024-8484 | REST API TO MiniProgram <= 4.7.1 - SQL Injection | rest api to miniprogram | 7.5 (v3.1) | High |
| CVE-2024-8522 | LearnPress < 4.2.7.1 - SQL Injection | learnpress | 7.5 (v3.1) | High |
| CVE-2024-8529 | LearnPress < 4.2.7.1 - SQL Injection | learnpress | 7.5 (v3.1) | High |
| CVE-2025-4396 | Relevanssi <= 4.24.4 (Free) - Unauthenticated SQL Injection | Relevanssi Premium | 7.5 (v3.1) | High |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code Execution | endpoint manager mobile | 7.5 (v3.1) | High |
| CVE-2026-10716 | Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation | Directus | 7.5 (v4.0) | High |
| CVE-2026-2413 | Ally – Web Accessibility & Usability <= 4.0.3 - SQL Injection | Ally – Web Accessibility & Usability | 7.5 (v3.1) | High |
| CVE-2026-3018 | WordPress Newsletters <= 4.13 - Unauthenticated SQL Injection | Newsletters | 7.5 (v3.1) | High |
| CVE-2026-3396 | WCAPF WooCommerce Ajax Product Filter - SQL Injection | WCAPF – Ajax Product Filter for WooCommerce | 7.5 (v3.1) | High |
| CVE-2026-4060 | Geo Mashup <= 1.13.18 - SQL Injection | Geo Mashup | 7.5 (v3.1) | High |
| CVE-2026-52476 | aiflowy <= 2.1.2 SQL Injection Vulnerability | aiflowy <= 2.1.2 | 7.5 (v3.1) | High |
| CVE-2026-52770 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki | yeswiki | 7.5 (v3.1) | High |
| CVE-2026-6854 | My Calendar < 3.7.9 - Unauthenticated SQL Injection | My Calendar – Accessible Event Manager | 7.5 (v3.1) | High |
| CVE-2026-78837 | A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2024-36683 | PrestaShop productsalert - SQL Injection | the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop | 7.3 (v3.1) | High |
| CVE-2024-48259 | Cloudlog - SQL Injection | cloudlog | 7.3 (v3.1) | High |
| CVE-2025-67405 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-67406 | Advocate office management system Arbitrary Code Execution Vulnerability | Advocate office management system | 7.3 (v3.1) | High |
| CVE-2025-67407 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-67408 | Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-69944 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2025-69945 | kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability | - | 7.3 (v3.1) | High |
| CVE-2018-10738 | NagiosXI <= 5.4.12 menuaccess.php - SQL injection | nagios xi | 7.2 (v3.0) | High |
| CVE-2019-9041 | ZZZCMS 1.6.1 - Remote Code Execution | zzzphp | 7.2 (v3.0) | High |
| CVE-2020-14883 | Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution | weblogic server | 7.2 (v3.1) | High |
| CVE-2021-24786 | Download Monitor < 4.4.5 - SQL Injection | download monitor | 7.2 (v3.1) | High |
| CVE-2022-0228 | Popup Builder < 4.0.7 - SQL Injection | popup builder | 7.2 (v3.1) | High |
| CVE-2022-31339 | simple inventory system SQL Injection Vulnerability | simple inventory system | 7.2 (v3.1) | High |
| CVE-2023-1211 | phpIPAM 1.5.1 - SQL Injection | phpipam | 7.2 (v3.1) | High |
| CVE-2026-27834 | Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter | piwigo | 7.2 (v3.1) | High |
| CVE-2026-27885 | Piwigo: SQL Injection in Activity.getList | piwigo | 7.2 (v3.1) | High |
| CVE-2026-39343 | ChurchCRM has a SQL Injection in Event Type Editor (Admin) | churchcrm | 7.2 (v3.1) | High |
| CVE-2018-25392 | MaxOn ERP Software 8.x-9.x SQL Injection via nomor Parameter | MaxOn ERP | 7.1 (v4.0) | High |
| CVE-2018-25410 | SIM-PKH 2.4.1 SQL Injection via media.php id Parameter | SIM-PKH | 7.1 (v4.0) | High |
| CVE-2018-25429 | Paroiciel 11.20 SQL Injection via zProIdPro Parameter | Paroiciel | 7.1 (v4.0) | High |
| CVE-2018-25430 | Paroiciel 11.20 SQL Injection via eGeqIdEquipe Parameter | Paroiciel | 7.1 (v4.0) | High |
| CVE-2018-25431 | No-Cms 1.0 SQL Injection via order_by Parameter | No-CMS | 7.1 (v4.0) | High |
| CVE-2019-25664 | SuiteCRM 7.10.7 SQL Injection via record Parameter | suitecrm | 7.1 (v4.0) | High |
| CVE-2019-25749 | Joomla J-CruisePortal 6.0.4 SQL Injection via cruises | j-cruiseportal | 7.1 (v4.0) | High |
| CVE-2019-25761 | Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id | joomcrm | 7.1 (v4.0) | High |
| CVE-2026-16007 | Authenticated SQL Injection in AppFlowy | AppFlowy-Cloud | 7.1 (v4.0) | High |
| CVE-2026-18737 | Shlink Blind SQL Injection via tags/stats orderBy Parameter | Shlink | 7.1 (v4.0) | High |
| CVE-2026-33714 | Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2) | chamilo lms | 7.1 (v4.0) | High |
| CVE-2026-48231 | Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48232 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset Parameter | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48233 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset Parameter | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48234 | Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48236 | Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48237 | Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48238 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48239 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter | Tickets | 7.1 (v4.0) | High |
| CVE-2026-48240 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters | Tickets | 7.1 (v4.0) | High |
| CVE-2026-63080 | Aptabase SQL Injection via ClickHouse query backend | aptabase | 7.1 (v4.0) | High |
| CVE-2026-72607 | Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by Age | Koha | 7.1 (v3.1) | High |
| CVE-2026-72609 | Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl | Koha | 7.1 (v3.1) | High |
| CVE-2026-75132 | WAPT Server SQL Injection via /api/v3/hosts Endpoint | WAPT | 7.1 (v4.0) | High |
| CVE-2026-69704 | Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() | Atals-Livre | 7.0 (v4.0) | High |
| CVE-2024-10758 | NEWS-BUZZ News Management System 1.0 - SQL Injection | news-buzz | 6.9 (v4.0) | Medium |
| CVE-2024-7188 | Bylancer Quicklancer 2.4 G - SQL Injection | quicklancer | 6.9 (v4.0) | Medium |
| CVE-2026-15153 | WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search | WP Hotel Booking | 6.8 (v3.1) | Medium |
| CVE-2020-13945 | Apache APISIX - Insufficiently Protected Credentials | apisix | 6.5 (v3.1) | Medium |
| CVE-2021-39165 | Cachet <=2.3.18 - SQL Injection | cachet | 6.5 (v3.1) | Medium |
| CVE-2023-27167 | Suprema BioStar 2 v2.8.16 - SQL Injection | biostar 2 | 6.5 (v3.1) | Medium |
| CVE-2026-26379 | koha Server-Side Request Forgery Vulnerability | koha | 6.5 (v3.1) | Medium |
| CVE-2026-34788 | Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parameters | emlog | 6.5 (v3.1) | Medium |
| CVE-2026-39229 | Bolt CMS through 3.7.0 SQL Injection Vulnerability | - | 6.5 (v3.1) | Medium |
| CVE-2026-72608 | Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name | Koha | 6.5 (v3.1) | Medium |
| CVE-2012-5193 | Bitweaver 2.8.1 - Multiple Vulnerabilities | bitweaver | 6.1 (v3.1) | Medium |
| CVE-2018-7543 | WordPress Plugin Duplicator 1.2.32 - Cross-Site Scripting | duplicator | 6.1 (v3.1) | Medium |
| CVE-2019-14950 | WP Live Chat Support <= 8.0.27 — Stored Cross-Site Scripting | live chat | 6.1 (v3.0) | Medium |
| CVE-2023-3169 | tagDiv Composer < 4.2 - Stored Cross-Site Scripting | tagdiv composer | 6.1 (v3.1) | Medium |
| CVE-2023-5244 | Microweber < V.2.0 - Cross-Site Scripting | microweber | 6.1 (v3.1) | Medium |
| CVE-2024-28623 | RiteCMS 3.0.0 - Cross-site Scripting | ritecms | 6.1 (v3.1) | Medium |
| CVE-2026-18403 | LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB | LimeSurvey | 6.0 (v4.0) | Medium |
| CVE-2026-6428 | Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter | Koha | 5.6 (v4.0) | Medium |
| CVE-2025-6403 | Code-Projects School Fees Payment System 1.0 - SQL Injection | school fees payment system | 5.5 (v4.0) | Medium |
| CVE-2026-10178 | code-projects Online Music Site AdminEditAlbum.php sql injection | Online Music Site | 5.5 (v4.0) | Medium |
| CVE-2026-10186 | code-projects Online Hospital Management System patient.php sql injection | Online Hospital Management System | 5.5 (v4.0) | Medium |
| CVE-2026-10249 | itsourcecode Online Blood Bank Management System viewrequest.php sql injection | Online Blood Bank Management System | 5.5 (v4.0) | Medium |
| CVE-2026-10250 | itsourcecode Online Blood Bank Management System campsdetails.php sql injection | Online Blood Bank Management System | 5.5 (v4.0) | Medium |
| CVE-2026-10252 | itsourcecode Online House Rental System manage_tenant.php sql injection | Online House Rental System | 5.5 (v4.0) | Medium |
| CVE-2026-10253 | itsourcecode Online House Rental System manage_payment.php sql injection | Online House Rental System | 5.5 (v4.0) | Medium |
| CVE-2026-10260 | CodeAstro Online Job Portal delete-jobs.php sql injection | Online Job Portal | 5.5 (v4.0) | Medium |
| CVE-2026-10261 | CodeAstro Online Job Portal application_status.php sql injection | Online Job Portal | 5.5 (v4.0) | Medium |
| CVE-2026-10262 | code-projects Real State Services Login loginuser.php sql injection | Real State Services | 5.5 (v4.0) | Medium |
| CVE-2026-10263 | SourceCodester Computer Repair Shop Management System manage_product.php sql injection | Computer Repair Shop Management System | 5.5 (v4.0) | Medium |
| CVE-2026-10620 | code-projects Student Admission System index.php sql injection | Student Admission System | 5.5 (v4.0) | Medium |
| CVE-2026-11435 | Jinher OA nextselectplan.aspx sql injection | OA | 5.5 (v4.0) | Medium |
| CVE-2026-11456 | Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection | CRM | 5.5 (v4.0) | Medium |
| CVE-2026-11482 | SourceCodester Class and Exam Timetabling System archive5.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11483 | SourceCodester Class and Exam Timetabling System archive4.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11484 | SourceCodester Class and Exam Timetabling System archive3.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11485 | SourceCodester Class and Exam Timetabling System archive2.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11486 | SourceCodester Class and Exam Timetabling System archive1.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-11488 | code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection | Simple Flight Ticket Booking System | 5.5 (v4.0) | Medium |
| CVE-2026-11489 | code-projects Online Music Site AdminDeleteAlbum.php sql injection | Online Music Site | 5.5 (v4.0) | Medium |
| CVE-2026-11490 | code-projects Online Music Site Search.php sql injection | Online Music Site | 5.5 (v4.0) | Medium |
| CVE-2026-11501 | SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection | Hospitals Patient Records Management System | 5.5 (v4.0) | Medium |
| CVE-2026-11582 | CodeAstro Student Attendance Management System index.php sql injection | Student Attendance Management System | 5.5 (v4.0) | Medium |
| CVE-2026-16152 | SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16154 | SourceCodester Class and Exam Timetabling System edit_room1.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16227 | SourceCodester Class and Exam Timetabling System edit_subject.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16228 | SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16484 | SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-16765 | CodeAstro Online Classroom loginlinkadmin.php sql injection | Online Classroom | 5.5 (v4.0) | Medium |
| CVE-2026-19021 | SourceCodester Computer Repair Shop Management System Master.php delete_product sql injection | Computer Repair Shop Management System | 5.5 (v4.0) | Medium |
| CVE-2026-19343 | code-projects Task Management System AdminLogin.php sql injection | Task Management System | 5.5 (v4.0) | Medium |
| CVE-2026-19344 | code-projects Task Management System comment_count_user.php sql injection | Task Management System | 5.5 (v4.0) | Medium |
| CVE-2026-19710 | SourceCodester Simple Student Information System view_department.php sql injection | Simple Student Information System | 5.5 (v4.0) | Medium |
| CVE-2026-19899 | SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-19919 | code-projects Online Shopping System Login login.php sql injection | Online Shopping System | 5.5 (v4.0) | Medium |
| CVE-2026-19926 | Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection | Evergreen | 5.5 (v4.0) | Medium |
| CVE-2026-45376 | Decidim: Admin user search allows SQL injection through similarity-based sorting | decidim | 5.5 (v3.1) | Medium |
| CVE-2026-5368 | projectworlds Car Rental Project Parameter login.php sql injection | car rental project | 5.5 (v4.0) | Medium |
| CVE-2026-5551 | itsourcecode Free Hotel Reservation System Parameter login.php sql injection | Free Hotel Reservation System | 5.5 (v4.0) | Medium |
| CVE-2026-5554 | code-projects Concert Ticket Reservation System Parameter process_search.php sql injection | Concert Ticket Reservation System | 5.5 (v4.0) | Medium |
| CVE-2026-5555 | code-projects Concert Ticket Reservation System Parameter login.php sql injection | Concert Ticket Reservation System | 5.5 (v4.0) | Medium |
| CVE-2026-5564 | code-projects Simple Laundry System Parameter searchguest.php sql injection | Simple Laundry System | 5.5 (v4.0) | Medium |
| CVE-2026-5565 | code-projects Simple Laundry System Parameter delmemberinfo.php sql injection | Simple Laundry System | 5.5 (v4.0) | Medium |
| CVE-2026-5575 | SourceCodester/jkev Record Management System Login index.php sql injection | Record Management System | 5.5 (v4.0) | Medium |
| CVE-2026-5577 | Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection | cross browser fingerprinting | 5.5 (v4.0) | Medium |
| CVE-2026-5634 | projectworlds Car Rental Project Parameter book_car.php sql injection | Car Rental Project | 5.5 (v4.0) | Medium |
| CVE-2026-5672 | code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection | Simple IT Discussion Forum | 5.5 (v4.0) | Medium |
| CVE-2026-5805 | code-projects Easy Blog Site contact_us.php sql injection | Easy Blog Site | 5.5 (v4.0) | Medium |
| CVE-2026-5813 | PHPGurukul Online Course Registration check_availability.php sql injection | Online Course Registration | 5.5 (v4.0) | Medium |
| CVE-2026-5814 | PHPGurukul Online Course Registration check_availability.php sql injection | Online Course Registration | 5.5 (v4.0) | Medium |
| CVE-2026-5824 | code-projects Simple Laundry System userchecklogin.php sql injection | Simple Laundry System | 5.5 (v4.0) | Medium |
| CVE-2026-5829 | code-projects Simple IT Discussion Forum content.php sql injection | Simple IT Discussion Forum | 5.5 (v4.0) | Medium |
| CVE-2026-75014 | SourceCodester Pet Grooming Management Software get_barcode_data.php sql injection | Pet Grooming Management Software | 5.5 (v4.0) | Medium |
| CVE-2026-75079 | SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-75080 | SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-75986 | code-projects Online Job Portal System Password Recovery ForPass.php sql injection | Online Job Portal System | 5.5 (v4.0) | Medium |
| CVE-2026-76574 | code-projects Hospital Information System User Login UsersController.php login sql injection | Hospital Information System | 5.5 (v4.0) | Medium |
| CVE-2026-76762 | code-projects Assessment Management welcome.php sql injection | Assessment Management | 5.5 (v4.0) | Medium |
| CVE-2026-76764 | code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection | Employee Management System | 5.5 (v4.0) | Medium |
| CVE-2026-76990 | code-projects Simple Inventory System delete.php sql injection | Simple Inventory System | 5.5 (v4.0) | Medium |
| CVE-2026-76996 | SourceCodester Simple Online Food Ordering System view_order.php sql injection | Simple Online Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-77019 | CodeAstro Apartment Visitor Management System forgotpw.php sql injection | Apartment Visitor Management System | 5.5 (v4.0) | Medium |
| CVE-2026-78143 | code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection | Barangay Resident Profiling Management System | 5.5 (v4.0) | Medium |
| CVE-2026-78171 | itsourcecode Sales and Inventory System processlogin.php sql injection | Sales and Inventory System | 5.5 (v4.0) | Medium |
| CVE-2026-78199 | SourceCodester Simple Online Food Ordering System view_prod.php sql injection | Simple Online Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-78201 | itsourcecode Payroll System admin_class.php login sql injection | Payroll System | 5.5 (v4.0) | Medium |
| CVE-2026-78244 | itsourcecode Real Estate Management System search.php sql injection | Real Estate Management System | 5.5 (v4.0) | Medium |
| CVE-2026-78246 | itsourcecode Online Clinic Management System Admin Login login.php sql injection | Online Clinic Management System | 5.5 (v4.0) | Medium |
| CVE-2026-79804 | SililaWijesinghe Food Ordering System search.php sql injection | Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-79845 | code-projects Simple Inventory System edit.php sql injection | Simple Inventory System | 5.5 (v4.0) | Medium |
| CVE-2026-82600 | SeaCMS zyapi.php sql injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-82610 | itsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82611 | itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82612 | itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82613 | itsourcecode Online Medicine Delivery System Product Search index.php loadResultList sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82614 | itsourcecode Online Medicine Delivery System Product Category Filter index.php loadResultList sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82615 | itsourcecode Online Medicine Delivery System Password Recovery passwordrecover.php find_phone sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-82701 | code-projects Online Shopping System Search Functionality action.php sql injection | Online Shopping System | 5.5 (v4.0) | Medium |
| CVE-2026-84111 | Chanjet CRM jxf_dump_table.php sql injection | CRM | 5.5 (v4.0) | Medium |
| CVE-2026-85187 | itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injection | Online Medicine Delivery System | 5.5 (v4.0) | Medium |
| CVE-2026-85225 | code-projects Doctor Appointment System patient_login.php sql injection | Doctor Appointment System | 5.5 (v4.0) | Medium |
| CVE-2026-85379 | light0011 cms Query Builder ChapterController.class.php searchChapter sql injection | cms | 5.5 (v4.0) | Medium |
| CVE-2026-85397 | code-projects Hospital Information System addReq.php findBySearch sql injection | Hospital Information System | 5.5 (v4.0) | Medium |
| CVE-2026-85398 | code-projects Hospital Information System viewReq.php viewReq sql injection | Hospital Information System | 5.5 (v4.0) | Medium |
| CVE-2026-85399 | code-projects Hospital Information System PrespController.php getSinglePresp sql injection | Hospital Information System | 5.5 (v4.0) | Medium |
| CVE-2026-85402 | code-projects Doctor Appointment System booking.php sql injection | Doctor Appointment System | 5.5 (v4.0) | Medium |
| CVE-2026-85403 | code-projects Doctor Appointment System contactus.php sql injection | Doctor Appointment System | 5.5 (v4.0) | Medium |
| CVE-2026-85512 | SourceCodester Class and Exam Timetabling System session.php authorization | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-85516 | code-projects Vehicle Management System busprofile.php sql injection | Vehicle Management System | 5.5 (v4.0) | Medium |
| CVE-2026-86168 | code-projects Content Management System login.php sql injection | Content Management System | 5.5 (v4.0) | Medium |
| CVE-2026-86180 | code-projects Task Management System In PHP Login index.php sql injection | Task Management System In PHP | 5.5 (v4.0) | Medium |
| CVE-2026-86208 | SourceCodester Class and Exam Timetabling System delete_teacher.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86209 | SourceCodester Class and Exam Timetabling System delete_user.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86210 | SourceCodester Class and Exam Timetabling System delete_user_account.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86211 | rabindralamsal inventory-management-system Login index.php sql injection | inventory-management-system | 5.5 (v4.0) | Medium |
| CVE-2026-86213 | Mstfakts College-Management-System Search university.php mysqli_query sql injection | College-Management-System | 5.5 (v4.0) | Medium |
| CVE-2026-86220 | SourceCodester Class and Exam Timetabling System modal_add_course.php mysqli_query sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86221 | SourceCodester Class and Exam Timetabling System modal_add_course1.php mysqli_query sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86222 | SourceCodester Class and Exam Timetabling System modal_add_course2.php mysqli_query sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86223 | SourceCodester Class and Exam Timetabling System modal_add_coursea.php mysqli_query sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86224 | SourceCodester Class and Exam Timetabling System modal_add_product.php mysqli_query sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86225 | SourceCodester Class and Exam Timetabling System modal_add_room.php mysqli_query sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-86268 | itsourcecode School Management System User_Login.php sql injection | School Management System | 5.5 (v4.0) | Medium |
| CVE-2026-86298 | SourceCodester Class and Exam Timetabling System delete_subject.php sql injection | Class and Exam Timetabling System | 5.5 (v4.0) | Medium |
| CVE-2026-9355 | SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injection | Hospitals Patient Records Management System | 5.5 (v4.0) | Medium |
| CVE-2026-9356 | SourceCodester Hospitals Patient Records Management System manage_history.php sql injection | Hospitals Patient Records Management System | 5.5 (v4.0) | Medium |
| CVE-2026-9364 | projectworlds Online Art Gallery Shop adminHome.php sql injection | Online Art Gallery Shop | 5.5 (v4.0) | Medium |
| CVE-2026-9383 | itsourcecode Electronic Judging System login.php sql injection | Electronic Judging System | 5.5 (v4.0) | Medium |
| CVE-2026-9469 | yashpokharna2555 StudentManagementSystem success.php sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2026-9470 | yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2026-9525 | itsourcecode Electronic Judging System edit_judge.php sql injection | Electronic Judging System | 5.5 (v4.0) | Medium |
| CVE-2026-9526 | itsourcecode Electronic Judging System edit_team.php sql injection | Electronic Judging System | 5.5 (v4.0) | Medium |
| CVE-2026-9528 | itsourcecode Electronic Judging System delete_judge.php sql injection | Electronic Judging System | 5.5 (v4.0) | Medium |
| CVE-2026-9573 | itsourcecode Student Transcript Processing System index.php sql injection | Student Transcript Processing System | 5.5 (v4.0) | Medium |
| CVE-2026-9574 | itsourcecode Student Transcript Processing System trans.php sql injection | Student Transcript Processing System | 5.5 (v4.0) | Medium |
| CVE-2026-9575 | itsourcecode Student Transcript Processing System index.php sql injection | Student Transcript Processing System | 5.5 (v4.0) | Medium |
| CVE-2026-9584 | code-projects Project Management System Login chk.php sql injection | Project Management System | 5.5 (v4.0) | Medium |
| CVE-2026-9606 | itsourcecode Courier Management System manage_user.php sql injection | Courier Management System | 5.5 (v4.0) | Medium |
| CVE-2023-6030 | LogDash Activity Log <= 1.1.3 - SQL Injection | logdash activity log | 5.4 (v3.1) | Medium |
| CVE-2026-26378 | koha Arbitrary Code Execution Vulnerability | koha | 5.4 (v3.1) | Medium |
| CVE-2026-38467 | the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerability | the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 | 5.4 (v3.1) | Medium |
| CVE-2016-1910 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | netweaver | 5.3 (v3.0) | Medium |
| CVE-2016-2388 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | netweaver application server java | 5.3 (v3.1) | Medium |
| CVE-2024-28397 | pyload-ng js2py - Remote Code Execution | pyload | 5.3 (v3.1) | Medium |
| CVE-2026-47720 | FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdString | FUXA | 5.3 (v3.1) | Medium |
| CVE-2026-5606 | PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection | Online Shopping Portal Project | 5.3 (v4.0) | Medium |
| CVE-2026-78864 | liketrek TREK Journey Entry Update journey.controller.t journeyService.updateEntry sql injection | TREK | 5.3 (v4.0) | Medium |
| CVE-2026-85205 | itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injection | Online Medicine Delivery System | 5.3 (v4.0) | Medium |
| CVE-2026-9524 | xianrendzw EasyReport REST Endpoint execute sql injection | EasyReport | 5.3 (v4.0) | Medium |
| CVE-2012-5192 | Bitweaver 2.8.1 - Multiple Vulnerabilities | bitweaver | 5.0 (v2.0) | Medium |
| CVE-2024-24050 | Workout Journal App 1.0 - Stored XSS | workout journal app | 4.7 (v3.1) | Medium |
| CVE-2014-9146 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 4.3 (v2.0) | Medium |
| CVE-2026-38468 | the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerability | the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 | 4.3 (v3.1) | Medium |
| CVE-2026-72610 | Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation | Koha | 4.3 (v3.1) | Medium |
| CVE-2026-14238 | Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report | vitepos | 4.1 (v3.1) | Medium |
| CVE-2014-1222 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | vtiger crm | 4.0 (v2.0) | Medium |
| CVE-2026-15381 | WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter | WP Go Maps | 3.7 (v3.1) | Low |
| CVE-2025-10592 | itsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injection | online public access catalog | 2.1 (v4.0) | Low |
| CVE-2025-13811 | jsnjfz WebStack-Guns PageFactory.java sql injection | webstack-guns | 2.1 (v4.0) | Low |
| CVE-2025-8266 | ChanCMS <= 3.1. - Remote Code Execution | chancms | 2.1 (v4.0) | Low |
| CVE-2026-10170 | code-projects Visitor Management System phone_0.php sql injection | Visitor Management System | 2.1 (v4.0) | Low |
| CVE-2026-10193 | OFCMS ComnController ComnController.java query sql injection | OFCMS | 2.1 (v4.0) | Low |
| CVE-2026-10202 | OFCMS JSON Query SystemDictController.java query sql injection | OFCMS | 2.1 (v4.0) | Low |
| CVE-2026-10203 | OFCMS JSON Query SystemParamController.java query sql injection | OFCMS | 2.1 (v4.0) | Low |
| CVE-2026-10204 | OFCMS JSON Query SysUserController.java query sql injection | OFCMS | 2.1 (v4.0) | Low |
| CVE-2026-10209 | code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection | Online Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-10256 | itsourcecode Content Management System save_comment.php sql injection | Content Management System | 2.1 (v4.0) | Low |
| CVE-2026-10258 | itsourcecode Content Management System add_sub_topic.php sql injection | Content Management System | 2.1 (v4.0) | Low |
| CVE-2026-10265 | itsourcecode Content Management System edit_topic.php sql injection | Content Management System | 2.1 (v4.0) | Low |
| CVE-2026-10286 | CodeAstro Payroll System home_employee.php sql injection | Payroll System | 2.1 (v4.0) | Low |
| CVE-2026-10297 | itsourcecode Fees Management System manage_course.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10302 | itsourcecode Fees Management System manage_fee.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10568 | itsourcecode Fees Management System manage_payment.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10808 | itsourcecode Fees Management System manage_student.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10809 | itsourcecode Fees Management System manage_user.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10811 | itsourcecode Fees Management System receipt.php sql injection | Fees Management System | 2.1 (v4.0) | Low |
| CVE-2026-10874 | projectworlds Online Art Gallery Shop Project adminHome.php sql injection | Online Art Gallery Shop Project | 2.1 (v4.0) | Low |
| CVE-2026-10875 | projectworlds Online Art Gallery Shop Project adminHome.ph sql injection | Online Art Gallery Shop Project | 2.1 (v4.0) | Low |
| CVE-2026-11412 | Jinher OA GetFormSn.aspx sql injection | OA | 2.1 (v4.0) | Low |
| CVE-2026-11475 | Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection | student-management-system | 2.1 (v4.0) | Low |
| CVE-2026-11476 | Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization | student-management-system | 2.1 (v4.0) | Low |
| CVE-2026-11495 | CodeAstro Ingredients Stock Management System add_stock.php sql injection | Ingredients Stock Management System | 2.1 (v4.0) | Low |
| CVE-2026-11506 | CodeAstro Leave Management System search_staff_for_deletion.php sql injection | Leave Management System | 2.1 (v4.0) | Low |
| CVE-2026-11507 | CodeAstro Leave Management System delete_leave_type.php sql injection | Leave Management System | 2.1 (v4.0) | Low |
| CVE-2026-11508 | CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection | Leave Management System | 2.1 (v4.0) | Low |
| CVE-2026-11510 | CodeAstro Leave Management System add_leave.php sql injection | Leave Management System | 2.1 (v4.0) | Low |
| CVE-2026-11513 | itsourcecode Hospital Management System adminaccount.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-11514 | itsourcecode Hospital Management System addpatient.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-11558 | CodeAstro Payroll System home_salary.php sql injection | Payroll System | 2.1 (v4.0) | Low |
| CVE-2026-11559 | CodeAstro Payroll System view_account.php sql injection | Payroll System | 2.1 (v4.0) | Low |
| CVE-2026-11583 | CodeAstro Student Attendance Management System createClass.php sql injection | Student Attendance Management System | 2.1 (v4.0) | Low |
| CVE-2026-11584 | CodeAstro Student Attendance Management System createClass.php edit sql injection | Student Attendance Management System | 2.1 (v4.0) | Low |
| CVE-2026-11585 | CodeAstro Student Attendance Management System createClassArms.php sql injection | Student Attendance Management System | 2.1 (v4.0) | Low |
| CVE-2026-16131 | itsourcecode Hospital Management System prescriptionrecord.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-16244 | itsourcecode Hospital Management System prescriptionorderreport.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-16334 | itsourcecode Hospital Management System prescriptionorder.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-16449 | zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection | ZS-Admin | 2.1 (v4.0) | Low |
| CVE-2026-18766 | chetans9 core-php-admin-panel customers.php sql injection | core-php-admin-panel | 2.1 (v4.0) | Low |
| CVE-2026-18896 | lavkush-maurya Student-Registration-System changepass.php sql injection | Student-Registration-System | 2.1 (v4.0) | Low |
| CVE-2026-19020 | itsourcecode Hospital Management System servicetype.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19067 | itsourcecode Hospital Management System treatment.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19068 | itsourcecode Hospital Management System treatmentdetail.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19069 | itsourcecode Hospital Management System treatmentrecord.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19070 | itsourcecode Hospital Management System viewadmin.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19071 | itsourcecode Hospital Management System viewappointment.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19347 | itsourcecode Hospital Management System viewdoctor.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19364 | itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19767 | itsourcecode Hospital Management System viewdoctortimings.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19894 | itsourcecode Hospital Management System viewmedicine.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19917 | code-projects Online Food Order System delete_food_items1.php sql injection | Online Food Order System | 2.1 (v4.0) | Low |
| CVE-2026-19920 | code-projects Online Shopping System action.php sql injection | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-19921 | code-projects Online Shopping System homeaction.php sql injection | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-19923 | code-projects Online Shopping System checkout_process.php sql injection | Online Shopping System | 2.1 (v4.0) | Low |
| CVE-2026-19934 | itsourcecode Hospital Management System vieworder.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19972 | itsourcecode Hospital Management System viewpatient.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-19973 | itsourcecode Hospital Management System viewpaymentreport.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-20000 | itsourcecode Hospital Management System viewprescriptionrecord.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-5206 | code-projects Simple Gym Management System Payment sql injection | Simple Gym Management System | 2.1 (v4.0) | Low |
| CVE-2026-5537 | halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection | CourseSEL | 2.1 (v4.0) | Low |
| CVE-2026-5543 | PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection | User Registration & Login and User Management System | 2.1 (v4.0) | Low |
| CVE-2026-5552 | PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5553 | itsourcecode Online Cellphone System Parameter available.php sql injection | Online Cellphone System | 2.1 (v4.0) | Low |
| CVE-2026-5558 | PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection | PHPGurukul Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5560 | PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5578 | CodeAstro Online Classroom Parameter addassessment.php sql injection | Online Classroom | 2.1 (v4.0) | Low |
| CVE-2026-5579 | CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection | Online Classroom | 2.1 (v4.0) | Low |
| CVE-2026-5580 | CodeAstro Online Classroom Parameter addvideos.php sql injection | Online Classroom | 2.1 (v4.0) | Low |
| CVE-2026-5583 | PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5620 | itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection | Construction Management System | 2.1 (v4.0) | Low |
| CVE-2026-5635 | PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5636 | PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection | Online Shopping Portal Project | 2.1 (v4.0) | Low |
| CVE-2026-5675 | itsourcecode Construction Management System Parameter borrowed_tool.php sql injection | Construction Management System | 2.1 (v4.0) | Low |
| CVE-2026-5681 | itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection | sanitize or validate this input | 2.1 (v4.0) | Low |
| CVE-2026-5823 | itsourcecode Construction Management System borrowed_tool_report.php sql injection | Construction Management System | 2.1 (v4.0) | Low |
| CVE-2026-7196 | CodeAstro Online Classroom guestdetails sql injection | Online Classroom | 2.1 (v4.0) | Low |
| CVE-2026-75086 | itsourcecode Hospital Management System viewroom.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-75087 | itsourcecode Hospital Management System viewdepartment.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-75088 | itsourcecode Hospital Management System viewbilling.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-75876 | xianrendzw EasyReport Move Operations ModuleController.java sql injection | EasyReport | 2.1 (v4.0) | Low |
| CVE-2026-76785 | amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injection | Mini-Inventory-and-Sales-Management-System | 2.1 (v4.0) | Low |
| CVE-2026-76991 | itsourcecode Hospital Management System viewappointmentapproved.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-77025 | itsourcecode Hospital Management System viewappointmentpending.php sql injection | Hospital Management System | 2.1 (v4.0) | Low |
| CVE-2026-78056 | sambitraj Student-Management-System Dashboard sql injection | Student-Management-System | 2.1 (v4.0) | Low |
| CVE-2026-78057 | sambitraj Student-Management-System Management Mutation sql injection | Student-Management-System | 2.1 (v4.0) | Low |
| CVE-2026-78112 | itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection | Hospital Management System Project in PHP | 2.1 (v4.0) | Low |
| CVE-2026-78185 | itsourcecode Sales and Inventory System cust_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-78200 | itsourcecode Library Management System editbooks.php sql injection | Library Management System | 2.1 (v4.0) | Low |
| CVE-2026-78656 | itsourcecode Sales and Inventory System cust_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-8231 | CodeAstro Online Catering Ordering System deleteorder.php sql injection | Online Catering Ordering System | 2.1 (v4.0) | Low |
| CVE-2026-82421 | itsourcecode Sales and Inventory System emp_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82422 | itsourcecode Sales and Inventory System emp_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82424 | PHPGurukul Student Information System student_edit1.php sql injection | Student Information System | 2.1 (v4.0) | Low |
| CVE-2026-82484 | itsourcecode Sales and Inventory System emp_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82485 | itsourcecode Sales and Inventory System pro_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82540 | itsourcecode Sales and Inventory System cust_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82541 | itsourcecode Sales and Inventory System sup_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82545 | itsourcecode Sales and Inventory System sup_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82609 | itsourcecode Sales and Inventory System inv_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-82696 | itsourcecode Sales and Inventory System inv_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-84109 | Xinhu Rainrock RockOA webmainAction.php getOrder sql injection | Rainrock RockOA | 2.1 (v4.0) | Low |
| CVE-2026-84153 | Xinhu Rainrock RockOA index.php toaddval sql injection | Rainrock RockOA | 2.1 (v4.0) | Low |
| CVE-2026-85383 | itsourcecode Sales and Inventory System inv_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86163 | itsourcecode Sales and Inventory System pro_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86164 | itsourcecode Sales and Inventory System trans_view.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86170 | DefaultFuction CRM edit.php sql injection | CRM | 2.1 (v4.0) | Low |
| CVE-2026-86171 | DefaultFuction CRM delete.php sql injection | CRM | 2.1 (v4.0) | Low |
| CVE-2026-86172 | DefaultFuction CRM delete.php sql injection | CRM | 2.1 (v4.0) | Low |
| CVE-2026-86232 | itsourcecode Sales and Inventory System sup_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86233 | itsourcecode Sales and Inventory System us_del.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86234 | itsourcecode Sales and Inventory System cust_transac.php add sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86235 | itsourcecode Sales and Inventory System pos_transac.php add sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86236 | itsourcecode Sales and Inventory System pro_transac.php add sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86245 | itsourcecode Sales and Inventory System sup_transac.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86265 | itsourcecode Sales and Inventory System us_transac.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86267 | itsourcecode Information System Society Membership System check_student.php sql injection | Information System Society Membership System | 2.1 (v4.0) | Low |
| CVE-2026-86269 | itsourcecode Sales and Inventory System emp_edit1.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86270 | itsourcecode Sales and Inventory System settings_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86291 | itsourcecode Sales and Inventory System us_edit1.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86309 | itsourcecode Sales and Inventory System pro_searchfrm.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86310 | itsourcecode Sales and Inventory System cust_edit1.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86517 | itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-86518 | code-projects Student Crud Operation edit.php sql injection | Student Crud Operation | 2.1 (v4.0) | Low |
| CVE-2026-86675 | itsourcecode Sales and Inventory System us_edit.php sql injection | Sales and Inventory System | 2.1 (v4.0) | Low |
| CVE-2026-9342 | SourceCodester Hospitals Patient Records Management System view_history.php sql injection | Hospitals Patient Records Management System | 2.1 (v4.0) | Low |
| CVE-2026-9450 | code-projects Employee Management System psubmit.php sql injection | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9451 | code-projects Employee Management System applyleaveprocess.php sql injection | Employee Management System | 2.1 (v4.0) | Low |
| CVE-2026-9542 | CodeAstro Leave Management System add_staff.php sql injection | Leave Management System | 2.1 (v4.0) | Low |
| CVE-2026-9607 | itsourcecode Courier Management System parcel_list.php sql injection | Courier Management System | 2.1 (v4.0) | Low |
| CVE-2026-10155 | Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection | Multi-Store Inventory Management System | 2.0 (v4.0) | Low |
| CVE-2026-10171 | code-projects Online Music Site AdminUpdateAlbum.php sql injection | Online Music Site | 2.0 (v4.0) | Low |
| CVE-2026-19787 | SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection | Air Cargo Management System | 2.0 (v4.0) | Low |
| CVE-2026-19925 | SourceCodester Stock Management System Master.php delete_supplier sql injection | Stock Management System | 2.0 (v4.0) | Low |
| CVE-2026-85643 | code-projects Online Shopping System adduser.php mysqli_query sql injection | Online Shopping System | 2.0 (v4.0) | Low |
| CVE-2026-86667 | aircheng-org iWebShop-5 member.php member_list sql injection | iWebShop-5 | 2.0 (v4.0) | Low |
| CVE-2022-43128 | Dreamer CMS v4.0.0 - SQL Injection | - | N/A | N/A |
| CVE-2026-38626 | Garlic-Hub v1.0.1 SQL Injection Vulnerability | - | N/A | N/A |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.