On this page

Atomicorp WAF Rule 380122

Rule Summary

  • Rule ID: 380122
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections
  • Observed CWEs: CWE-22 (1), CWE-74 (282), CWE-79 (11), CWE-89 (751), CWE-94 (2), CWE-200 (1), CWE-266 (1), CWE-284 (1), CWE-285 (1), CWE-287 (2), CWE-306 (1), CWE-352 (1), CWE-434 (1), CWE-862 (2), CWE-863 (1), CWE-918 (1)
  • Revision: 5
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request URI, Request headers, Request cookies, Request arguments, JSON request data, SOAP request data, XML request data
  • Rule action: deny
  • HTTP status: 403
  • Public tags: SQLi
  • Logging: log, auditlog

Description

This rule detects when either database store procedure or function content is detected in a POST from a client to the server. In most cases this indicates that the server is being attacked. If you believe this is a false positive, please report it our security team. This rule is unlikely to generate false positives, and we do not recommend you disable this rule.

Troubleshooting

False Positives

If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system.

Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2024-30498CRM Perks Forms <= 1.1.4 - SQL Injectioncrm perks forms10.0 (v3.1)Critical
CVE-2026-72899Metabase SQL injection via public card or dashboardMetabase10.0 (v4.0)Critical
CVE-2024-51482ZoneMinder v1.37.* <= 1.37.64 - SQL Injectionzoneminder9.9 (v3.1)Critical
CVE-2026-51366Bottinelli Informatica Vedo Suite v.1.2.5 Arbitrary Code Execution VulnerabilityBottinelli Informatica Vedo Suite v.1.2.59.9 (v3.1)Critical
CVE-2026-69083SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContentsiyuan9.9 (v4.0)Critical
CVE-2026-69084SiYuan - SQL Executionsiyuan9.9 (v4.0)Critical
CVE-2026-69085SiYuan before v3.7.3 SQL Injection via searchDocssiyuan9.9 (v4.0)Critical
CVE-2014-9148Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms9.8 (v3.0)Critical
CVE-2015-3934Fiyo CMS 2.0_1.9.1 - SQL Injectionfiyo cms9.8 (v3.0)Critical
CVE-2015-9323404 to 301 <= 2.0.2 - Authenticated Blind SQL Injection404 to 3019.8 (v3.1)Critical
CVE-2017-17970Muviko 1.1 - SQL Injectionmuviko9.8 (v3.0)Critical
CVE-2017-17999RISE 1.9 - 'search' SQL Injectionrise ultimate project manager9.8 (v3.0)Critical
CVE-2017-9834WordPress Plugin WatuPRO 5.5.1 - SQL Injectionwatupro9.8 (v3.0)Critical
CVE-2018-11511ASUSTOR ADM 3.1.0.RFQ3 - SQL Injectionasustor data master9.8 (v3.0)Critical
CVE-2018-16159WordPress Gift Voucher <4.1.8 - Blind SQL Injectiongift vouchers9.8 (v3.0)Critical
CVE-2018-18923Ticketly 1.0 - 'kind_id' SQL Injectionticketly9.8 (v3.0)Critical
CVE-2018-7538Tuleap 9.17.99.189 - Blind SQL Injectiontuleap9.8 (v3.0)Critical
CVE-2020-11530WordPress Chop Slider 3 - Blind SQL Injectionchop slider9.8 (v3.1)Critical
CVE-2020-17463Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)fuel cms9.8 (v3.1)Critical
CVE-2020-18662Gnuboard5 5.3.2.8 - SQL Injectiongnuboard9.8 (v3.1)Critical
CVE-2020-27481Good Layers LMS Plugin <= 2.1.4 - SQL Injectiongood learning management system9.8 (v3.1)Critical
CVE-2020-27615WordPress Loginizer < 1.6.4 – Unauthenticated SQL Injection via log Parameterloginizer9.8 (v3.1)Critical
CVE-2020-35545Spotweb 1.4.9 - 'search' SQL Injectionspotweb9.8 (v3.1)Critical
CVE-2020-8656EyesOfNetwork - Hardcoded API Key & SQL Injectioneyesofnetwork9.8 (v3.1)Critical
CVE-2021-2413910Web Photo Gallery < 1.5.55 - SQL Injectionphoto gallery9.8 (v3.1)Critical
CVE-2021-24442Wordpress Polls Widget < 1.5.3 - SQL Injectionpoll, survey, questionnaire and voting system9.8 (v3.1)Critical
CVE-2021-24731Pie Register < 3.7.1.6 - SQL Injectionpie register9.8 (v3.1)Critical
CVE-2021-24762WordPress Perfect Survey <1.5.2 - SQL Injectionperfect survey9.8 (v3.1)Critical
CVE-2021-24827WordPress Asgaros Forum <1.15.13 - SQL Injectionasgaros forum9.8 (v3.1)Critical
CVE-2021-24849WCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL Injectionfrontend manager for woocommerce along with bookings subscription listings compatible9.8 (v3.1)Critical
CVE-2021-24931WordPress Secure Copy Content Protection and Content Locking <2.8.2 - SQL Injectionsecure copy content protection and content locking9.8 (v3.1)Critical
CVE-2021-24943Registrations for the Events Calendar < 2.7.6 - SQL Injectionregistrations for the events calendar9.8 (v3.1)Critical
CVE-2021-24946WordPress Modern Events Calendar <6.1.5 - Blind SQL Injectionmodern events calendar lite9.8 (v3.1)Critical
CVE-2021-25114WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injectionpaid memberships pro9.8 (v3.1)Critical
CVE-2021-26599ImpressCMS < 1.4.3 - SQL Injectionimpresscms9.8 (v3.1)Critical
CVE-2021-27314Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system9.8 (v3.1)Critical
CVE-2021-3018IPeakCMS 3.5 - SQL Injectionipeakcms9.8 (v3.1)Critical
CVE-2021-3110PrestaShop 1.7.7.0 - SQL Injectionprestashop9.8 (v3.1)Critical
CVE-2022-0349WordPress NotificationX <2.3.9 - SQL Injectionnotificationx9.8 (v3.1)Critical
CVE-2022-0412WordPress TI WooCommerce Wishlist <1.40.1 - SQL Injectionti woocommerce wishlist9.8 (v3.1)Critical
CVE-2022-0592MapSVG < 6.2.20 - Unauthenticated SQLimapsvg9.8 (v3.1)Critical
CVE-2022-0658CommonsBooking < 2.6.8 - SQL Injectioncommonsbooking9.8 (v3.1)Critical
CVE-2022-0693WordPress Master Elements <=8.0 - SQL Injectionmaster elements9.8 (v3.1)Critical
CVE-2022-0747Infographic Maker iList < 4.3.8 - SQL Injectioninfographic maker9.8 (v3.1)Critical
CVE-2022-0760WordPress Simple Link Directory <7.7.2 - SQL injectionsimple link directory9.8 (v3.1)Critical
CVE-2022-0769Users Ultra <= 3.1.0 - SQL Injectionusers ultra9.8 (v3.1)Critical
CVE-2022-0773Documentor <= 1.5.3 - Unauthenticated SQL Injectiondocumentor9.8 (v3.1)Critical
CVE-2022-0783Multiple Shipping Address Woocommerce < 2.0 - SQL Injectionmultiple shipping addresses for woocommerce9.8 (v3.1)Critical
CVE-2022-0784WordPress Title Experiments Free <9.0.1 - SQL Injectiontitle experiments free9.8 (v3.1)Critical
CVE-2022-0785WordPress Daily Prayer Time <2022.03.01 - SQL Injectiondaily prayer time9.8 (v3.1)Critical
CVE-2022-0786WordPress KiviCare <2.3.9 - SQL Injectionkivicare9.8 (v3.1)Critical
CVE-2022-0787Limit Login Attempts (Spam Protection) < 5.1 - SQL Injectionlimit login attempts9.8 (v3.1)Critical
CVE-2022-0788WordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL Injectionwp fundraising donation and crowdfunding platform9.8 (v3.1)Critical
CVE-2022-0826WordPress WP Video Gallery <=1.7.1 - SQL Injectionwp-video-gallery-free9.8 (v3.1)Critical
CVE-2022-0827WordPress Best Books <=2.6.3 - SQL Injectionbestbooks9.8 (v3.1)Critical
CVE-2022-0846SpeakOut Email Petitions < 2.14.15.1 - SQL Injectionspeakout! email petitions9.8 (v3.1)Critical
CVE-2022-0867WordPress ARPrice <3.6.1 - SQL Injectionpricing table9.8 (v3.1)Critical
CVE-2022-0948WordPress Order Listener for WooCommerce <3.2.2 - SQL Injectionorder listener for woocommerce9.8 (v3.1)Critical
CVE-2022-0949WordPress Stop Bad Bots <6.930 - SQL Injectionblock and stop bad bots9.8 (v3.1)Critical
CVE-2022-1013WordPress Personal Dictionary <1.3.4 - Blind SQL Injectionpersonal dictionary9.8 (v3.1)Critical
CVE-2022-1057WordPress Pricing Deals for WooCommerce <=2.0.2.02 - SQL Injectionpricing deals for woocommerce9.8 (v3.1)Critical
CVE-2022-1950Youzify < 1.2.0 - Unauthenticated SQLiyouzify9.8 (v3.1)Critical
CVE-2022-22897PrestaShop AP Pagebuilder <= 2.4.4 - SQL Injectionap pagebuilder9.8 (v3.1)Critical
CVE-2022-24223Atom CMS v2.0 - SQL Injectionatomcms9.8 (v3.1)Critical
CVE-2022-2467Garage Management System 1.0 - SQL Injectiongarage management system9.8 (v3.1)Critical
CVE-2022-27984Cuppa CMS v1.0 - SQL injectioncuppacms9.8 (v3.1)Critical
CVE-2022-28032Atom CMS v2.0 - SQL Injectionatomcms9.8 (v3.1)Critical
CVE-2022-28033Atom.CMS 2.0 - SQL Injectionatomcms9.8 (v3.1)Critical
CVE-2022-2840Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLizephyr project manager9.8 (v3.1)Critical
CVE-2022-31340simple inventory system SQL Injection Vulnerabilitysimple inventory system9.8 (v3.1)Critical
CVE-2022-31976Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system9.8 (v3.1)Critical
CVE-2022-31977Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system9.8 (v3.1)Critical
CVE-2022-31978Online Fire Reporting System v1.0 - SQL injectiononline fire reporting system9.8 (v3.1)Critical
CVE-2022-33965WordPress Visitor Statistics <=5.7 - SQL Injectionwp visitor statistics9.8 (v3.1)Critical
CVE-2022-3481NotificationX Dropshipping < 4.4 - SQL Injectionwoocommerce dropshipping9.8 (v3.1)Critical
CVE-2022-40032Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)simple task managing system9.8 (v3.1)Critical
CVE-2022-4050WordPress JoomSport <5.2.8 - SQL Injectionjoomsport9.8 (v3.1)Critical
CVE-2022-4059Cryptocurrency Widgets Pack < 2.0 - SQL Injectioncryptocurrency widgets pack9.8 (v3.1)Critical
CVE-2022-4117WordPress IWS Geo Form Fields <=1.0 - SQL Injectioniws-geo-form-fields9.8 (v3.1)Critical
CVE-2022-44290WebTareas 2.4p5 - SQL Injectionwebtareas9.8 (v3.1)Critical
CVE-2022-44291WebTareas 2.4p5 - SQL Injectionwebtareas9.8 (v3.1)Critical
CVE-2022-44588Cryptocurrency Widgets Pack <= 1.8.1 - SQL Injectioncryptocurrency widgets pack9.8 (v3.1)Critical
CVE-2022-45805WordPress Paytm Payment Gateway <=2.7.3 - SQL Injectionpayment gateway9.8 (v3.1)Critical
CVE-2022-45808LearnPress Plugin < 4.2.0 - Unauthenticated Time-Based Blind SQLilearnpress9.8 (v3.1)Critical
CVE-2023-0037WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injectionmap builder for google maps9.8 (v3.1)Critical
CVE-2023-0600WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL Injectionwp visitor statistics9.8 (v3.1)Critical
CVE-2023-1730SupportCandy < 3.1.5 - Unauthenticated SQL Injectionsupportcandy9.8 (v3.1)Critical
CVE-2023-2130Purchase Order Management v1.0 - SQL Injectionpurchase order management system9.8 (v3.1)Critical
CVE-2023-23488WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injectionpaid memberships pro9.8 (v3.1)Critical
CVE-2023-23489WordPress Easy Digital Downloads 3.1.0.2/3.1.0.3 - SQL Injectioneasy digital downloads9.8 (v3.1)Critical
CVE-2023-24000WordPress GamiPress <= 2.5.7 - SQL Injectiongamipress9.8 (v3.1)Critical
CVE-2023-27034Jms Blog - SQL Injectionjms blog9.8 (v3.1)Critical
CVE-2023-27637PrestaShop tshirtecommerce Module - SQL Injectioncustom product designer9.8 (v3.1)Critical
CVE-2023-27638tshirtecommerce PrestaShop Module - SQL Injectionprestashop9.8 (v3.1)Critical
CVE-2023-27847PrestaShop xipblog - SQL Injectionxipblog9.8 (v3.1)Critical
CVE-2023-30150PrestaShop leocustomajax 1.0 & 1.0.0 - SQL Injectionleocustomajax9.8 (v3.1)Critical
CVE-2023-30192PrestaShop 'possearchproducts' <= 1.7 - SQL Injectionpossearchproducts9.8 (v3.1)Critical
CVE-2023-3077MStore API < 3.9.8 - SQL Injectionmstore api9.8 (v3.1)Critical
CVE-2023-3197WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injectionmstore api9.8 (v3.1)Critical
CVE-2023-34751bloofoxCMS v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical
CVE-2023-34752bloofoxCMS v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical
CVE-2023-34753bloofoxCMS v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical
CVE-2023-34754Bloofox v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical
CVE-2023-34755bloofoxCMS v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical
CVE-2023-34756Bloofox v0.5.2.1 - SQL Injectionbloofoxcms9.8 (v3.1)Critical
CVE-2023-39361Cacti 1.2.24 - SQL Injectioncacti9.8 (v3.1)Critical
CVE-2023-39650PrestaShop Theme Volty CMS Blog - SQL Injectiontheme volty cms blog9.8 (v3.1)Critical
CVE-2023-39796WBCE 1.6.0 - Unauthenticated SQL injectionwbce cms9.8 (v3.1)Critical
CVE-2023-43373Hoteldruid v3.0.5 - SQL Injectionhoteldruid9.8 (v3.1)Critical
CVE-2023-43374Hoteldruid v3.0.5 - SQL Injectionhoteldruid9.8 (v3.1)Critical
CVE-2023-4490WordPress Job Portal < 2.0.6 - SQL Injectionwp job portal9.8 (v3.1)Critical
CVE-2023-48084Nagios XI < 5.11.3 - SQL Injectionnagios xi9.8 (v3.1)Critical
CVE-2023-4974Academy LMS 6.2 - SQL Injectionacademy lms9.8 (v3.1)Critical
CVE-2023-50839JS Help Desk <= 2.8.1 - SQL Injectionjs help desk9.8 (v3.1)Critical
CVE-2023-5652WP Hotel Booking <= 2.0.7 - SQL Injectionwp hotel booking9.8 (v3.1)Critical
CVE-2023-6360WordPress My Calendar <3.4.22 - SQL Injectionmy calendar9.8 (v3.1)Critical
CVE-2024-1061WordPress HTML5 Video Player - SQL Injectionhtml5 video player9.8 (v3.1)Critical
CVE-2024-1512MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injectionmasterstudy lms9.8 (v3.1)Critical
CVE-2024-1698NotificationX <= 2.8.2 - SQL Injectionnotificationx9.8 (v3.1)Critical
CVE-2024-24495Daily Habit Tracker 1.0 - SQL Injectiondaily habit tracker9.8 (v3.1)Critical
CVE-2024-2621Fujian Kelixin Communication - Command Injectionkelixin communication command and dispatch9.8 (v3.1)Critical
CVE-2024-27956WordPress Automatic Plugin <= 3.92.0 - SQL Injectionautomatic9.8 (v3.1)Critical
CVE-2024-2876Wordpress Email Subscribers by Icegram Express - SQL InjectionEmail Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress9.8 (v3.1)Critical
CVE-2024-30490ProfileGrid <= 5.7.8 - SQL Injectionprofilegrid9.8 (v3.1)Critical
CVE-2024-30502WP Travel Engine <= 5.7.9 - SQL Injectionwp travel engine9.8 (v3.1)Critical
CVE-2024-3552Web Directory Free < 1.7.0 - SQL Injectionweb directory free9.8 (v3.1)Critical
CVE-2024-3605WP Hotel Booking <= 2.1.0 - SQL Injectionwp hotel booking9.8 (v3.1)Critical
CVE-2024-36412SuiteCRM - SQL Injectionsuitecrm9.8 (v3.1)Critical
CVE-2024-38773FormLift for Infusionsoft Web Forms <= 7.5.17 - SQL Injectionformlift for infusionsoft web forms9.8 (v3.1)Critical
CVE-2024-43144Cost Calculator Builder <= 3.2.15 - SQL Injectioncost calculator builder9.8 (v3.1)Critical
CVE-2024-43360ZoneMinder - SQL Injectionzoneminder9.8 (v3.1)Critical
CVE-2024-43917WordPress TI WooCommerce Wishlist Plugin <= 2.8.2 - SQL Injectionti woocommerce wishlist9.8 (v3.1)Critical
CVE-2024-43965SendGrid for WordPress <= 1.4 - SQL Injectionsendgrid9.8 (v3.1)Critical
CVE-2024-5057WordPress Easy Digital Downloads <= 3.2.12 - SQL Injectioneasy digital downloads9.8 (v3.1)Critical
CVE-2024-51211openSIS Classic v9.1 - SQL Injectionopensis9.8 (v3.1)Critical
CVE-2024-5765WpStickyBar <= 2.1.0 - SQL Injectionwpstickybar9.8 (v3.1)Critical
CVE-2024-6159Push Notification for Post and BuddyPress <= 1.93 - SQL Injectionpush notification for post and buddypress9.8 (v3.1)Critical
CVE-2024-6205PayPlus Payment Gateway < 6.6.9 - SQL Injectionpayplus payment gateway9.8 (v3.1)Critical
CVE-2024-6265UsersWP <= 1.2.10 - Unauthenticated SQL Injectionuserswp9.8 (v3.1)Critical
CVE-2024-6924TrueBooker <= 1.0.2 - SQL Injectiontruebooker9.8 (v3.1)Critical
CVE-2024-6926Viral Signup <= 2.1 - SQL Injectionviral signup9.8 (v3.1)Critical
CVE-2024-6928Opti Marketing <= 2.0.9 - SQL Injectionopti marketing9.8 (v3.1)Critical
CVE-2024-7854Woo Inquiry <= 0.1 - SQL Injectionwoo inquiry9.8 (v3.1)Critical
CVE-2024-8911LatePoint <= 5.0.11 - SQL Injectionlatepoint9.8 (v3.1)Critical
CVE-2025-24799GLPI < 10.0.17 - Pre-Auth SQL Injectionglpi9.8 (v3.1)Critical
CVE-2025-57631tduck Arbitrary Code Execution Vulnerabilitytduck9.8 (v3.1)Critical
CVE-2025-65336Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-65340kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-67066oasys sysoa version 1.0 Arbitrary Code Execution Vulnerabilityoasys sysoa version 1.09.8 (v3.1)Critical
CVE-2025-67403Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-67404Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69930CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69931CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69933CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69934CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69935SQL Injection-9.8 (v3.1)Critical
CVE-2025-69936CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69937CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69938CodeAstro Membership Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69941SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69942kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69943SQL Injection-9.8 (v3.1)Critical
CVE-2025-69946SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69947SourceCodester Tailor Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-69948SourceCodester Modern Loan Management System 1.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2025-70149membership management system SQL Injection Vulnerabilitymembership management system9.8 (v3.1)Critical
CVE-2025-70150membership management system Missing Authorization Vulnerabilitymembership management system9.8 (v3.1)Critical
CVE-2025-70152scholars tracking system SQL Injection Vulnerabilityscholars tracking system9.8 (v3.1)Critical
CVE-2026-10880Unauthenticated SQL Injection in Osnexus QuantastorQuantaStor9.8 (v3.1)Critical
CVE-2026-21875ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL Injectionclipbucket9.8 (v3.1)Critical
CVE-2026-46670YesWiki: Unauthenticated SQL Injectionyeswiki9.8 (v3.1)Critical
CVE-2026-48528Metacat has an unauthenticated SQL injection vulnerabilitymetacat9.8 (v3.1)Critical
CVE-2026-51775Fastadmin v.1.6.1.20250430 SQL Injection VulnerabilityFastadmin v.1.6.1.202504309.8 (v3.1)Critical
CVE-2026-52348cool-admin-java 8.0.0 SQL Injection Vulnerabilitycool-admin-java 8.0.09.8 (v3.1)Critical
CVE-2026-52472Wgcloud 3.6.4 SQL Injection VulnerabilityWgcloud 3.6.49.8 (v3.1)Critical
CVE-2026-67689FineAdmin V1.0 Arbitrary Code Execution VulnerabilityFineAdmin V1.09.8 (v3.1)Critical
CVE-2026-68000MCMS <=6.2.0 is vulnerable to SQL injection VulnerabilityMCMS <=6.2.0 is vulnerable to SQL injection9.8 (v3.1)Critical
CVE-2026-69240Sequelize: SQL Injection (Oracle DB)sequelize9.8 (v3.1)Critical
CVE-2026-75330super-diamond-server <= 1.3.3 is vulnerable to SQL injection Vulnerabilitysuper-diamond-server <= 1.3.3 is vulnerable to SQL injection9.8 (v3.1)Critical
CVE-2026-75336Funiture 1.0.0 SQL Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-79569Movie_Recommend v1.0.0 SQL Injection VulnerabilityMovie Recommend v1.0.09.8 (v3.1)Critical
CVE-2026-79570mfish-nocode-pro v1.0.0 SQL Injection Vulnerabilitymfish-nocode-pro v1.0.09.8 (v3.1)Critical
CVE-2019-16383MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injectionmoveit transfer9.4 (v3.1)Critical
CVE-2026-39342ChurchCRM has a SQL injection searchwhat parameter via QueryView.phpchurchcrm9.4 (v4.0)Critical
CVE-2026-44262Scramble Laravel - Remote Code Executionscramble9.4 (v3.1)Critical
CVE-2016-20096Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jspLinknat VOS30009.3 (v4.0)Critical
CVE-2023-28787Quiz and Survey Master <= 8.1.4 - SQL InjectionQuiz And Survey Master9.3 (v3.1)Critical
CVE-2024-32128WordPress Realtyna Organic IDX Plugin <= 4.14.4 - SQL InjectionRealtyna Organic IDX plugin9.3 (v3.1)Critical
CVE-2025-1023ChurchCRM - SQL Injectionchurchcrm9.3 (v4.0)Critical
CVE-2025-22785Course Booking System <= 6.0.6 - SQL InjectionCourse Booking System9.3 (v3.1)Critical
CVE-2025-32969XWiki REST API Query - SQL Injectionxwiki9.3 (v4.0)Critical
CVE-2025-48281MyStyle Custom Product Designer <= 3.21.1 - SQL InjectionMyStyle Custom Product Designer9.3 (v3.1)Critical
CVE-2025-54726WordPress JS Archive List <= 6.1.5 - SQL InjectionJS Archive List9.3 (v3.1)Critical
CVE-2026-40329SQL Injection vulnerability via sortBy in beanFeedMasaCMS9.3 (v4.0)Critical
CVE-2026-40330Masa CMS SQL injection via sortDirection parameter in beanFeedMasaCMS9.3 (v4.0)Critical
CVE-2026-42647JoomSport <= 5.7.7 - SQL Injectionjoomsport-sports-league-results-management9.3 (v3.1)Critical
CVE-2026-54836YMC Filter - SQL InjectionYMC Filter9.3 (v3.1)Critical
CVE-2026-63106ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.phpReady eCommerce9.3 (v4.0)Critical
CVE-2026-65761Joomla Easy Store - SQL InjectionEasy Store9.3 (v4.0)Critical
CVE-2026-81672Multiple Vulnerabilities in TOOOLS' iSquadiSquad9.3 (v4.0)Critical
CVE-2026-81673Multiple Vulnerabilities in TOOOLS' iSquadiSquad9.3 (v4.0)Critical
CVE-2026-81674Multiple Vulnerabilities in TOOOLS' iSquadiSquad9.3 (v4.0)Critical
CVE-2026-81675Multiple Vulnerabilities in TOOOLS' iSquadiSquad9.3 (v4.0)Critical
CVE-2026-82526R2R 3.6.6 SQL Injection via Vector Index Creation EndpointR2R9.3 (v4.0)Critical
CVE-2026-9586Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injectionswitchvox9.3 (v4.0)Critical
CVE-2024-9465Palo Alto Expedition - SQL Injectionexpedition9.2 (v4.0)Critical
CVE-2021-37593PEEL Shopping 9.3.0 - 'id' Time-based SQL Injectionpeel shopping9.1 (v3.1)Critical
CVE-2022-44727PrestaShop lgcookieslaw - SQL Injectioneu cookie law gdpr9.1 (v3.1)Critical
CVE-2024-5975CZ Loan Management <= 1.1 - SQL Injectioncz loan management9.1 (v3.1)Critical
CVE-2025-50455the CodeIgniter Query Builder Arbitrary Code Execution Vulnerabilitythe CodeIgniter Query Builder9.1 (v3.1)Critical
CVE-2026-15360Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_argsAjax Load More9.1 (v3.1)Critical
CVE-2026-16532Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission FormLink Library9.1 (v3.1)Critical
CVE-2026-73069Twenty: SQL Injection in the searchVector Field Settings Allows Arbitrary PostgreSQL Executiontwenty9.1 (v3.1)Critical
CVE-2026-72851Budibase before 3.40.0 SQL Injection via Unauthenticated Webhookserver9.0 (v4.0)Critical
CVE-2016-20062Simply Poll 1.4.1 Plugin for WordPress SQL InjectionSimply Poll8.8 (v4.0)High
CVE-2017-20243WordPress Car Park Booking Plugin SQL Injection via space_idCar Park Booking System8.8 (v4.0)High
CVE-2017-20247WordPress Plugin PICA Photo Gallery 1.0 SQL InjectionPICA Photo Gallery8.8 (v4.0)High
CVE-2017-20249WordPress Plugin Apptha Slider Gallery 1.0 SQL InjectionApptha Slider Gallery8.8 (v4.0)High
CVE-2017-20260Joomla! Component Price Alert 3.0.2 SQL Injectionprice alert8.8 (v4.0)High
CVE-2017-20261Joomla! Component Bargain Product VM3 1.0 SQL Injectionbargain product vm38.8 (v4.0)High
CVE-2017-20263Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via locationfocalpoint8.8 (v4.0)High
CVE-2017-20266Joomla SP Movie Database 1.3 SQL Injection via searchwordstandard pro movie database8.8 (v4.0)High
CVE-2017-20267Joomla! Component Calendar Planner 1.0.1 SQL Injectioncalendar planner8.8 (v4.0)High
CVE-2017-20268Joomla! Component Zap Calendar Lite 4.3.4 SQL Injectionzap calendar lite8.8 (v4.0)High
CVE-2017-20269Joomla! Component KissGallery 1.0.0 SQL Injectionkissgallery8.8 (v4.0)High
CVE-2017-20271Joomla StreetGuessr Game 1.1.8 SQL Injection via catidstreetguessr game8.8 (v4.0)High
CVE-2017-20272Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_idultimate property listing8.8 (v4.0)High
CVE-2017-20273Joomla Event Registration Pro Calendar 4.1.3 SQL Injectionevent registration pro calendar8.8 (v4.0)High
CVE-2017-20274Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpathlearning management system king8.8 (v4.0)High
CVE-2017-20275Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameterbridge8.8 (v4.0)High
CVE-2017-20276Joomla! Component SIMGenealogy 2.1.5 SQL Injectionsimgenealogy8.8 (v4.0)High
CVE-2017-20277Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_authorjoomla joomrecipe8.8 (v4.0)High
CVE-2017-20278Joomla JoomRecipe 1.0.3 SQL Injection via category parameterjoomrecipe8.8 (v4.0)High
CVE-2017-20279Joomla Payage 2.05 SQL Injection via aid Parameterjoomla payage8.8 (v4.0)High
CVE-2017-20280Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parametermyportfolio8.8 (v4.0)High
CVE-2017-20281Joomla! Component Extra Search 2.2.8 SQL Injectionextra search8.8 (v4.0)High
CVE-2017-20282Joomla! Component jCart for OpenCart 2.0 SQL Injectionjcart for opencart8.8 (v4.0)High
CVE-2018-25340Smartshop 1 SQL Injection via category.phpSmartshop8.8 (v4.0)High
CVE-2018-25341Smartshop 1 SQL Injection via product.php id ParameterSmartshop8.8 (v4.0)High
CVE-2018-25342Smartshop 1 SQL Injection via search.phpSmartshop8.8 (v4.0)High
CVE-2018-25348Joomla! Component Ek Rishta 2.10 SQL Injection via user_detailEk Rishta8.8 (v4.0)High
CVE-2018-25351Joomla! Component EkRishta 2.10 SQL Injection via usernameEkRishta8.8 (v4.0)High
CVE-2018-25362Twitter-Clone 1 SQL Injection via follow.phpPHP-Twitter-Clone8.8 (v4.0)High
CVE-2018-25364Twitter-Clone 1 SQL Injection via search.phpPHP-Twitter-Clone8.8 (v4.0)High
CVE-2018-25371mooSocial Store Plugin 2.6 SQL Injection via product parametermooSocial Store Plugin8.8 (v4.0)High
CVE-2018-25372MedDream PACS Server Premium 6.7.1.1 SQL Injection via emailPACS Server Premium8.8 (v4.0)High
CVE-2018-25385E-Registrasi Pencak Silat 18.10 SQL Injection via id_partaiRegistrasi Pencak Silat8.8 (v4.0)High
CVE-2018-25386HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.phpHaPe PKH8.8 (v4.0)High
CVE-2018-25394Kados R10 GreenBee SQL Injection via update_release.phpKados R10 GreenBee8.8 (v4.0)High
CVE-2018-25395Kados R10 GreenBee SQL Injection via update_feature.phpKados R10 GreenBee8.8 (v4.0)High
CVE-2018-25411MGB OpenSource Guestbook 0.7.0.2 SQL Injection via email.phpMGB OpenSource Guestbook8.8 (v4.0)High
CVE-2018-25413AiOPMSD Final 1.0.0 SQL Injection via search.phpAiOPMSD Final8.8 (v4.0)High
CVE-2018-25414AiOPMSD Final 1.0.0 SQL Injection via actor.phpAiOPMSD Final8.8 (v4.0)High
CVE-2018-25416AiOPMSD Final 1.0.0 SQL Injection via country.phpAiOPMSD Final8.8 (v4.0)High
CVE-2018-25417AiOPMSD Final 1.0.0 SQL Injection via quality.phpAiOPMSD Final8.8 (v4.0)High
CVE-2018-25418AiOPMSD Final 1.0.0 SQL Injection via year.phpAiOPMSD Final8.8 (v4.0)High
CVE-2018-25419AiOPMSD Final 1.0.0 SQL Injection via genre.phpAiOPMSD Final8.8 (v4.0)High
CVE-2018-25420AiOPMSD Final 1.0.0 SQL Injection via watch.phpAiOPMSD Final8.8 (v4.0)High
CVE-2018-25422MOGG web simulator Script All Version SQL Injection via play.phpMOGG web simulator Script8.8 (v4.0)High
CVE-2018-25424Gate Pass Management System 2.1 SQL Injection via login-exec.phpGate Pass Management System8.8 (v4.0)High
CVE-2018-25425Yot CMS 3.3.1 SQL Injection via aid and cid ParametersYot CMS8.8 (v4.0)High
CVE-2018-25428Paroiciel 11.20 SQL Injection via tRecIdListe ParameterParoiciel8.8 (v4.0)High
CVE-2018-25433Joomla JE Photo Gallery 1.1 SQL Injection via categoryidJE Photo Gallery8.8 (v4.0)High
CVE-2018-25434WP AutoSuggest 0.24 SQL Injection via autosuggest.phpWP AutoSuggest8.8 (v4.0)High
CVE-2019-25662ResourceSpace 8.6 SQL Injection via watched_searches.phpresourcespace8.8 (v4.0)High
CVE-2019-25668News Website Script 2.0.5 SQL Injection via index.phpnews website script8.8 (v4.0)High
CVE-2019-25669qdPM 9.1 SQL Injection via search_by_extrafields Parameterqdpm8.8 (v4.0)High
CVE-2019-25675eDirectory All Versions SQL Injection Authentication Bypassedirectory8.8 (v4.0)High
CVE-2019-25678C4G BLIS 3.4 SQL Injection via users_select.phpcomputing for good&#x27;s basic laboratory information system8.8 (v4.0)High
CVE-2019-25680Advance Gift Shop Pro Script 2.0.3 SQL Injection via searchadvance gift shop pro script8.8 (v4.0)High
CVE-2019-25684OpenDocMan 1.3.4 SQL Injection via where Parameteropendocman8.8 (v4.0)High
CVE-2019-25694Kados R10 GreenBee SQL Injection via user2resetkados8.8 (v4.0)High
CVE-2019-25728Care2x 2.7 Hospital Information System SQL Injection via ck_configCare2x8.8 (v4.0)High
CVE-2019-25730Listing Hub CMS 1.0 SQL Injection via pages.php idListing Hub CMS8.8 (v4.0)High
CVE-2019-25732PHP EI-Tube Script 3 SQL Injection via search parameterEI-Tube8.8 (v4.0)High
CVE-2019-25745WordPress Plugin Google Review Slider 6.1 SQL Injection via tidGoogle Review Slider8.8 (v4.0)High
CVE-2019-25748Joomla JHotelReservation 6.0.7 SQL Injection via search-hotelsjhotelreservation8.8 (v4.0)High
CVE-2019-25750Joomla J-MultipleHotelReservation 6.0.7 SQL Injectionmultiplehotelreservation8.8 (v4.0)High
CVE-2019-25751Joomla J-ClassifiedsManager 3.0.5 SQL Injectionclassifiedsmanager8.8 (v4.0)High
CVE-2019-25752Joomla! Component J-BusinessDirectory 4.9.7 SQL Injectionj-businessdirectory8.8 (v4.0)High
CVE-2019-25756Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboardvaccount8.8 (v4.0)High
CVE-2020-15876SQL Injection-8.8 (v3.1)High
CVE-2020-15878SQL Injection-8.8 (v3.1)High
CVE-2020-6010WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated)learnpress8.8 (v3.1)High
CVE-2021-47928Opencart TMD Vendor System 3.x Blind SQL Injection via product routeExtension TMD Vendor System8.8 (v4.0)High
CVE-2021-47930Balbooa Joomla Forms Builder 2.0.6 SQL Injection UnauthenticatedBalbooa Joomla Forms Builder8.8 (v4.0)High
CVE-2022-0439Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injectionemail subscribers &amp; newsletters8.8 (v3.1)High
CVE-2022-3142NEX-Forms Plugin < 7.9.7 - SQL Injectionnex-forms8.8 (v3.1)High
CVE-2022-3768WordPress WPSmartContracts <1.3.12 - SQL Injectionwpsmartcontracts8.8 (v3.1)High
CVE-2023-0261WordPress WP TripAdvisor Review Slider <10.8 - Authenticated SQL Injectionwp tripadvisor review slider8.8 (v3.1)High
CVE-2023-0630Slimstat Analytics < 4.9.3.3 Subscriber - SQL Injectionslimstat analytics8.8 (v3.1)High
CVE-2023-7137Client Details System 1.0 - SQL Injectionclient details system8.8 (v3.1)High
CVE-2024-1751Tutor LMS <= 2.1.10 - SQL Injectiontutor lms8.8 (v3.1)High
CVE-2024-35584openSIS < 9.1 - SQL Injectionopensis8.8 (v3.1)High
CVE-2025-45868LogicalDOC Enterprise up to and for v9.1.1 SQL Injection Vulnerability-8.8 (v3.1)High
CVE-2026-31069BillaBear (all versions prior to Jan 2026) SQL Injection VulnerabilityBillaBear (all versions prior to Jan 2026)8.8 (v3.1)High
CVE-2026-35395WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameterwegia8.8 (v3.1)High
CVE-2026-35470OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modalsopenstamanager8.8 (v3.1)High
CVE-2026-41075RT: SQL injection via entry_aggregator parameter in JSON searchrt8.8 (v3.1)High
CVE-2026-44741Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Paramepimcore8.8 (v3.1)High
CVE-2026-52775YesWiki Authenticated SQL Injection in ReactionManageryeswiki8.8 (v3.1)High
CVE-2026-55084SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Readdhis2-core8.8 (v3.1)High
CVE-2026-55509WsgiDAV: Blind SQL injection in the MySQL providerwsgidav8.8 (v4.0)High
CVE-2026-70369Koha - SQL Injection in reports/acquisitions_stats.plKoha8.8 (v3.1)High
CVE-2026-70370Koha - SQL Injection in reports/catalogue_stats.plKoha8.8 (v3.1)High
CVE-2026-70373Koha - SQL Injection in reports/issues_stats.plKoha8.8 (v3.1)High
CVE-2026-81676Multiple Vulnerabilities in TOOOLS' iSquadiSquad8.8 (v4.0)High
CVE-2026-81677Multiple Vulnerabilities in TOOOLS' iSquadiSquad8.8 (v4.0)High
CVE-2016-20097Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoadE-cology 8.08.7 (v4.0)High
CVE-2019-25765ASP-CMS SQL Injection via commentList.asp id ParameterASP-CMS8.7 (v4.0)High
CVE-2022-50997Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jspE-cology 9.08.7 (v4.0)High
CVE-2024-58374Hongjing e-HR Unauthenticated SQL Injection via getSdutyTreee-HR8.7 (v4.0)High
CVE-2026-23921Blind, read-only SQL injection in Zabbix API via sortfield parameterzabbix8.7 (v4.0)High
CVE-2026-27634Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filterpiwigo8.7 (v4.0)High
CVE-2026-31844Authenticated SQL Injection in Koha displayby parameter of suggestion.plkoha8.7 (v4.0)High
CVE-2026-34100Guardian Language-System SQL Injection via id Parameter in media.phplanguage-system8.7 (v4.0)High
CVE-2026-34101Guardian Language-System SQL Injection via id Parameter in text_file.phplanguage-system8.7 (v4.0)High
CVE-2026-34102Guardian Language-System SQL Injection via id Parameter in job_info_get.phplanguage-system8.7 (v4.0)High
CVE-2026-34103Guardian Language-System SQL Injection via id Parameter in subtitles.phplanguage-system8.7 (v4.0)High
CVE-2026-34104Guardian Language-System SQL Injection via name Parameter in designer.phplanguage-system8.7 (v4.0)High
CVE-2026-34105Guardian Language-System SQL Injection via id Parameter in translate_text.phplanguage-system8.7 (v4.0)High
CVE-2026-35184EcclesiaCRM has a Critical SQL Injectionecclesiacrm8.7 (v4.0)High
CVE-2026-41453Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameterlaravel-crm8.7 (v4.0)High
CVE-2026-44739Pimcore: SQL Injection in Custom Reports Column Configurationpimcore8.7 (v3.1)High
CVE-2026-44886Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL InjectionPi.Alert8.7 (v4.0)High
CVE-2026-50636LimeSurvey RemoteControl invite_participants/remind_participants SQL InjectionLimeSurvey8.7 (v4.0)High
CVE-2026-61518ISPConfig Authenticated SQL Injection via Remote API primary_id Parameterispconfig38.7 (v4.0)High
CVE-2026-72708SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee ParameterSPIP8.7 (v4.0)High
CVE-2026-82527R2R 3.6.6 SQL Injection via Retrieval Search Filter KeyR2R8.7 (v4.0)High
CVE-2026-82655Admidio before 5.0.12 SQL Injection via relation_type_listadmidio8.7 (v4.0)High
CVE-2026-84208AVideo User_Location Plugin Unauthenticated SQL InjectionAVideo8.7 (v4.0)High
CVE-2026-85155WWBN AVideo SQL Injection via get.json.php APIName channelsAVideo8.7 (v4.0)High
CVE-2026-87807siyuan before v3.8.2 SQL Injection via fullTextSearchBlocksiyuan8.7 (v4.0)High
CVE-2024-13726Themes Coder Ecommerce <= 1.3.4 - SQL Injectiontc-ecommerce8.6 (v3.1)High
CVE-2024-9186Automation By Autonami < 3.3.0 - SQL Injectionwp-marketing-automations8.6 (v3.1)High
CVE-2026-11349Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_moreModern Event Calendar Pro8.6 (v3.1)High
CVE-2026-12721Kirki < 6.0.13 - Unauthenticated SQL InjectionKirki8.6 (v3.1)High
CVE-2026-16061Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}Rest Routes8.6 (v3.1)High
CVE-2026-3326XStore Theme < 9.7.3 - SQL InjectionXstore8.6 (v3.1)High
CVE-2026-3430Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLiCreative Mail8.6 (v3.1)High
CVE-2026-39931OpenEMR Authenticated SQL Injection via backup.php Import Featureopenemr8.6 (v4.0)High
CVE-2026-42425OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQueryOpenKM Community Edition8.6 (v4.0)High
CVE-2026-73670CMS Admin SQL Injection via db_data.php table_name ParameterSaurus CMS Community Edition8.6 (v4.0)High
CVE-2026-73850Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase() Functionemlog8.6 (v4.0)High
CVE-2026-76205phpMyFAQ before 4.1.7 SQL Injection via Glossaryphpmyfaq8.6 (v4.0)High
CVE-2026-76635baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.phpbasercms8.6 (v4.0)High
CVE-2026-79322mageplaza blog SQL Injection Vulnerabilitymageplaza blog8.6 (v3.1)High
CVE-2026-81728Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keysdolibarr erp/crm8.6 (v4.0)High
CVE-2026-44238FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reportsfreepbx8.5 (v4.0)High
CVE-2026-44706Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Valueschatwoot8.5 (v3.1)High
CVE-2026-65707Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpointlikeshop8.5 (v4.0)High
CVE-2026-49489OpenCATS - SQL Injection in DataGrid sortDirection ParameterOpenCATS8.4 (v4.0)High
CVE-2026-64657Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQLbudibase8.4 (v3.1)High
CVE-2026-88890OpenPanel SQL Injection via unvalidated profile filter column identifieropenpanel8.4 (v4.0)High
CVE-2026-52771YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (ApiController::deletePage)yeswiki8.3 (v3.1)High
CVE-2020-26248PrestaShop Product Comments <4.2.0 - SQL Injectionproductcomments8.2 (v3.1)High
CVE-2026-14920AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] ParameterAcyMailing8.2 (v3.1)High
CVE-2026-15258Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed FilterProduct Feed Manager For WooCommerce8.1 (v3.1)High
CVE-2026-39341SQL injection in ChurchCRM.0churchcrm8.1 (v3.1)High
CVE-2024-32136BWL Advanced FAQ Manager 2.0.3 - Authenticated SQL InjectionBWL Advanced FAQ Manager7.6 (v3.1)High
CVE-2014-9145Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v2.0)High
CVE-2014-9147Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v3.0)High
CVE-2015-2196WordPress Spider Calendar <=1.4.9 - SQL Injectionspider calendar7.5 (v2.0)High
CVE-2020-22165PHPGurukul Hospital Management System 4.0 - SQL Injectionhospital management system7.5 (v3.1)High
CVE-2020-5766SRS Simple Hits Counter 1.0.3-1.0.4 - Unauthenticated Blind SQL Injectionsrs simple hits counter7.5 (v3.1)High
CVE-2021-24340WordPress Statistics <13.0.8 - Blind SQL Injectionwp statistics7.5 (v3.1)High
CVE-2021-25899Void Aural Rec Monitor 9.0.0.1 - SQL Injectionaurall rec monitor7.5 (v3.1)High
CVE-2021-27316Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system7.5 (v3.1)High
CVE-2021-27319Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system7.5 (v3.1)High
CVE-2021-27320Doctor Appointment System 1.0 - SQL Injectiondoctor appointment system7.5 (v3.1)High
CVE-2022-1453RSVPMaker <= 9.2.5 - SQL Injectionrsvpmaker7.5 (v3.1)High
CVE-2022-1768WordPress RSVPMaker <=9.3.2 - SQL Injectionrsvpmaker7.5 (v3.1)High
CVE-2022-24265Cuppa CMS v1.0 - SQL injectioncuppacms7.5 (v3.1)High
CVE-2022-24266Cuppa CMS v1.0 - SQL injectioncuppacms7.5 (v3.1)High
CVE-2023-32590Subscribe to Category <= 2.7.4 - SQL Injectionsubscribe to category7.5 (v3.1)High
CVE-2023-36284QloApps 1.6.0 - SQL Injectionqloapps7.5 (v3.1)High
CVE-2023-5203WP Sessions Time Monitoring Full Automatic <= 1.0.8 - SQL Injectionwp sessions time monitoring full automatic7.5 (v3.1)High
CVE-2023-5204WordPress AI ChatBot (WPBot) <= 4.8.9 - SQL Injectionwpbot7.5 (v3.1)High
CVE-2023-6063WP Fastest Cache 1.2.2 - Unauthenticated SQL Injectionwp fastest cache7.5 (v3.1)High
CVE-2023-6567LearnPress <= 4.2.5.7 - SQL Injectionlearnpress7.5 (v3.1)High
CVE-2024-0705Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injectionstripe payment plugin for woocommerce7.5 (v3.1)High
CVE-2024-11728KiviCare Clinic & Patient Management System (EHR) <= 3.6.4 - SQL Injectionkivicare7.5 (v3.1)High
CVE-2024-12025WordPress Collapsing Categories <= 3.0.8 - SQL InjectionCollapsing Categories7.5 (v3.1)High
CVE-2024-13322Ads Pro Plugin <= 4.88 - Unauthenticated SQL Injectionads pro7.5 (v3.1)High
CVE-2024-2879WordPress Plugin LayerSlider 7.9.11-7.10.0 - SQL Injectionlayerslider7.5 (v3.1)High
CVE-2024-8484REST API TO MiniProgram <= 4.7.1 - SQL Injectionrest api to miniprogram7.5 (v3.1)High
CVE-2024-8522LearnPress < 4.2.7.1 - SQL Injectionlearnpress7.5 (v3.1)High
CVE-2024-8529LearnPress < 4.2.7.1 - SQL Injectionlearnpress7.5 (v3.1)High
CVE-2025-13138WP Directory Kit <= 1.4.3 - Unauthenticated SQL InjectionWP Directory Kit7.5 (v3.1)High
CVE-2025-2221WordPress WPCOM Member <= 1.7.6 - SQL Injectionwpcom member7.5 (v3.1)High
CVE-2025-4396Relevanssi <= 4.24.4 (Free) - Unauthenticated SQL InjectionRelevanssi Premium7.5 (v3.1)High
CVE-2025-5287Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL InjectionLikes and Dislikes Plugin7.5 (v3.1)High
CVE-2025-6970WordPress Events Manager <= 7.0.3 - SQL Injectionevents manager7.5 (v3.1)High
CVE-2026-10716Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creationDirectus7.5 (v4.0)High
CVE-2026-12987Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking RegistrationEvents Manager7.5 (v3.1)High
CVE-2026-1581wpForo Forum <= 2.4.14 - SQL InjectionwpForo Forum7.5 (v3.1)High
CVE-2026-2413Ally – Web Accessibility & Usability <= 4.0.3 - SQL InjectionAlly – Web Accessibility & Usability7.5 (v3.1)High
CVE-2026-2416Geo Mashup <= 1.13.17 - SQL InjectionGeo Mashup7.5 (v3.1)High
CVE-2026-3018WordPress Newsletters <= 4.13 - Unauthenticated SQL InjectionNewsletters7.5 (v3.1)High
CVE-2026-3396WCAPF WooCommerce Ajax Product Filter - SQL InjectionWCAPF – Ajax Product Filter for WooCommerce7.5 (v3.1)High
CVE-2026-4060Geo Mashup <= 1.13.18 - SQL InjectionGeo Mashup7.5 (v3.1)High
CVE-2026-51077Dede CMS v.5.7.118 SQL Injection VulnerabilityDede CMS v.5.7.1187.5 (v3.1)High
CVE-2026-52476aiflowy <= 2.1.2 SQL Injection Vulnerabilityaiflowy <= 2.1.27.5 (v3.1)High
CVE-2026-52770Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswikiyeswiki7.5 (v3.1)High
CVE-2026-6854My Calendar < 3.7.9 - Unauthenticated SQL InjectionMy Calendar – Accessible Event Manager7.5 (v3.1)High
CVE-2026-78837A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 Vulnerability-7.5 (v3.1)High
CVE-2024-36683PrestaShop productsalert - SQL Injectionthe module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop7.3 (v3.1)High
CVE-2025-67405Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-7.3 (v3.1)High
CVE-2025-67406Advocate office management system Arbitrary Code Execution VulnerabilityAdvocate office management system7.3 (v3.1)High
CVE-2025-67407Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-7.3 (v3.1)High
CVE-2025-67408Sourcecodester CASAP Automated Enrollment System 1.0 SQL Injection Vulnerability-7.3 (v3.1)High
CVE-2025-69944kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-7.3 (v3.1)High
CVE-2025-69945kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-7.3 (v3.1)High
CVE-2025-69949kishan0725 Hospital Management System 4.0 SQL Injection Vulnerability-7.3 (v3.1)High
CVE-2018-1002000WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter7.2 (v3.0)High
CVE-2021-24554WordPress Paytm Donation <=1.3.2 - Authenticated SQL Injectionpaytm-pay7.2 (v3.1)High
CVE-2021-24786Download Monitor < 4.4.5 - SQL Injectiondownload monitor7.2 (v3.1)High
CVE-2021-24791Header Footer Code Manager < 1.1.14 - Admin+ SQL Injectionheader footer code manager7.2 (v3.1)High
CVE-2021-24862WordPress RegistrationMagic <5.0.1.6 - Authenticated SQL Injectionregistrationmagic7.2 (v3.1)High
CVE-2022-0228Popup Builder < 4.0.7 - SQL Injectionpopup builder7.2 (v3.1)High
CVE-2022-31339simple inventory system SQL Injection Vulnerabilitysimple inventory system7.2 (v3.1)High
CVE-2023-1211phpIPAM 1.5.1 - SQL Injectionphpipam7.2 (v3.1)High
CVE-2023-1408Video List Manager <= 1.7 - SQL Injectionvideo list manager7.2 (v3.1)High
CVE-2024-0566Smart Manager 8.27.0 - Post-Authenticated SQL Injectionsmart manager7.2 (v3.1)High
CVE-2024-8625WordPress TS Poll < 2.4.0 - SQL Injectionts poll7.2 (v3.1)High
CVE-2026-27834Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameterpiwigo7.2 (v3.1)High
CVE-2026-27885Piwigo: SQL Injection in Activity.getListpiwigo7.2 (v3.1)High
CVE-2026-39343ChurchCRM has a SQL Injection in Event Type Editor (Admin)churchcrm7.2 (v3.1)High
CVE-2018-25346WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.phpForm Maker7.1 (v4.0)High
CVE-2018-25352WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_idUltimate Form Builder Lite7.1 (v4.0)High
CVE-2018-25392MaxOn ERP Software 8.x-9.x SQL Injection via nomor ParameterMaxOn ERP7.1 (v4.0)High
CVE-2018-25410SIM-PKH 2.4.1 SQL Injection via media.php id ParameterSIM-PKH7.1 (v4.0)High
CVE-2018-25429Paroiciel 11.20 SQL Injection via zProIdPro ParameterParoiciel7.1 (v4.0)High
CVE-2018-25430Paroiciel 11.20 SQL Injection via eGeqIdEquipe ParameterParoiciel7.1 (v4.0)High
CVE-2018-25431No-Cms 1.0 SQL Injection via order_by ParameterNo-CMS7.1 (v4.0)High
CVE-2019-25664SuiteCRM 7.10.7 SQL Injection via record Parametersuitecrm7.1 (v4.0)High
CVE-2019-25749Joomla J-CruisePortal 6.0.4 SQL Injection via cruisesj-cruiseportal7.1 (v4.0)High
CVE-2019-25761Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_idjoomcrm7.1 (v4.0)High
CVE-2026-16007Authenticated SQL Injection in AppFlowyAppFlowy-Cloud7.1 (v4.0)High
CVE-2026-18737Shlink Blind SQL Injection via tags/stats orderBy ParameterShlink7.1 (v4.0)High
CVE-2026-33714Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)chamilo lms7.1 (v4.0)High
CVE-2026-48231Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple ParametersTickets7.1 (v4.0)High
CVE-2026-48232Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset ParameterTickets7.1 (v4.0)High
CVE-2026-48233Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset ParameterTickets7.1 (v4.0)High
CVE-2026-48234Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir ParametersTickets7.1 (v4.0)High
CVE-2026-48236Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple ParametersTickets7.1 (v4.0)High
CVE-2026-48237Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id ParametersTickets7.1 (v4.0)High
CVE-2026-48238Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id ParameterTickets7.1 (v4.0)High
CVE-2026-48239Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id ParameterTickets7.1 (v4.0)High
CVE-2026-48240Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id ParametersTickets7.1 (v4.0)High
CVE-2026-63080Aptabase SQL Injection via ClickHouse query backendaptabase7.1 (v4.0)High
CVE-2026-72607Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by AgeKoha7.1 (v3.1)High
CVE-2026-72609Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.plKoha7.1 (v3.1)High
CVE-2026-75132WAPT Server SQL Injection via /api/v3/hosts EndpointWAPT7.1 (v4.0)High
CVE-2026-69704Atals-Livre SQL Injection via Unsanitized GET Parameter in supp()Atals-Livre7.0 (v4.0)High
CVE-2024-10758NEWS-BUZZ News Management System 1.0 - SQL Injectionnews-buzz6.9 (v4.0)Medium
CVE-2024-7188Bylancer Quicklancer 2.4 G - SQL Injectionquicklancer6.9 (v4.0)Medium
CVE-2026-14872Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id ParameterDatabase for Contact Form 7, WPforms, Elementor forms6.8 (v3.1)Medium
CVE-2026-15153WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List SearchWP Hotel Booking6.8 (v3.1)Medium
CVE-2015-4062WordPress NewStatPress 0.9.8 - SQL Injectionnewstatpress6.5 (v2.0)Medium
CVE-2021-39165Cachet <=2.3.18 - SQL Injectioncachet6.5 (v3.1)Medium
CVE-2023-27167Suprema BioStar 2 v2.8.16 - SQL Injectionbiostar 26.5 (v3.1)Medium
CVE-2025-13652WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL InjectionCBX Bookmark & Favorite6.5 (v3.1)Medium
CVE-2026-14554Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s ParametersCheck & Log Email6.5 (v3.1)Medium
CVE-2026-16065Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV ImportWelcart e-Commerce6.5 (v3.1)Medium
CVE-2026-26379koha Server-Side Request Forgery Vulnerabilitykoha6.5 (v3.1)Medium
CVE-2026-34788Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parametersemlog6.5 (v3.1)Medium
CVE-2026-39229Bolt CMS through 3.7.0 SQL Injection Vulnerability-6.5 (v3.1)Medium
CVE-2026-72608Koha Community Koha - Stored SQL Injection via Patron Card Layout image_nameKoha6.5 (v3.1)Medium
CVE-2026-18403LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDBLimeSurvey6.0 (v4.0)Medium
CVE-2026-16949Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookupTerm Pages5.8 (v3.1)Medium
CVE-2026-6428Koha SQL Injection in reports/catalogue_out.pl via Filter URL ParameterKoha5.6 (v4.0)Medium
CVE-2025-6403Code-Projects School Fees Payment System 1.0 - SQL Injectionschool fees payment system5.5 (v4.0)Medium
CVE-2026-10178code-projects Online Music Site AdminEditAlbum.php sql injectionOnline Music Site5.5 (v4.0)Medium
CVE-2026-10186code-projects Online Hospital Management System patient.php sql injectionOnline Hospital Management System5.5 (v4.0)Medium
CVE-2026-10249itsourcecode Online Blood Bank Management System viewrequest.php sql injectionOnline Blood Bank Management System5.5 (v4.0)Medium
CVE-2026-10250itsourcecode Online Blood Bank Management System campsdetails.php sql injectionOnline Blood Bank Management System5.5 (v4.0)Medium
CVE-2026-10251itsourcecode Online House Rental System ajax.php login sql injectionOnline House Rental System5.5 (v4.0)Medium
CVE-2026-10252itsourcecode Online House Rental System manage_tenant.php sql injectionOnline House Rental System5.5 (v4.0)Medium
CVE-2026-10253itsourcecode Online House Rental System manage_payment.php sql injectionOnline House Rental System5.5 (v4.0)Medium
CVE-2026-10260CodeAstro Online Job Portal delete-jobs.php sql injectionOnline Job Portal5.5 (v4.0)Medium
CVE-2026-10261CodeAstro Online Job Portal application_status.php sql injectionOnline Job Portal5.5 (v4.0)Medium
CVE-2026-10262code-projects Real State Services Login loginuser.php sql injectionReal State Services5.5 (v4.0)Medium
CVE-2026-10263SourceCodester Computer Repair Shop Management System manage_product.php sql injectionComputer Repair Shop Management System5.5 (v4.0)Medium
CVE-2026-10620code-projects Student Admission System index.php sql injectionStudent Admission System5.5 (v4.0)Medium
CVE-2026-10704SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injectionPizzafy E-Commerce System5.5 (v4.0)Medium
CVE-2026-11435Jinher OA nextselectplan.aspx sql injectionOA5.5 (v4.0)Medium
CVE-2026-11456Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injectionCRM5.5 (v4.0)Medium
CVE-2026-11482SourceCodester Class and Exam Timetabling System archive5.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-11483SourceCodester Class and Exam Timetabling System archive4.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-11484SourceCodester Class and Exam Timetabling System archive3.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-11485SourceCodester Class and Exam Timetabling System archive2.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-11486SourceCodester Class and Exam Timetabling System archive1.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-11488code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injectionSimple Flight Ticket Booking System5.5 (v4.0)Medium
CVE-2026-11489code-projects Online Music Site AdminDeleteAlbum.php sql injectionOnline Music Site5.5 (v4.0)Medium
CVE-2026-11490code-projects Online Music Site Search.php sql injectionOnline Music Site5.5 (v4.0)Medium
CVE-2026-11501SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injectionHospitals Patient Records Management System5.5 (v4.0)Medium
CVE-2026-11582CodeAstro Student Attendance Management System index.php sql injectionStudent Attendance Management System5.5 (v4.0)Medium
CVE-2026-16152SourceCodester Class and Exam Timetabling System edit_rooma.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-16154SourceCodester Class and Exam Timetabling System edit_room1.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-16227SourceCodester Class and Exam Timetabling System edit_subject.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-16228SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-16484SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-16765CodeAstro Online Classroom loginlinkadmin.php sql injectionOnline Classroom5.5 (v4.0)Medium
CVE-2026-19021SourceCodester Computer Repair Shop Management System Master.php delete_product sql injectionComputer Repair Shop Management System5.5 (v4.0)Medium
CVE-2026-19196SourceCodester Photo Share Website ajax.php login sql injectionPhoto Share Website5.5 (v4.0)Medium
CVE-2026-19211SourceCodester Photo Share Website ajax.php signup sql injectionPhoto Share Website5.5 (v4.0)Medium
CVE-2026-19343code-projects Task Management System AdminLogin.php sql injectionTask Management System5.5 (v4.0)Medium
CVE-2026-19344code-projects Task Management System comment_count_user.php sql injectionTask Management System5.5 (v4.0)Medium
CVE-2026-19384SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injectionSimple Doctors Appointment System5.5 (v4.0)Medium
CVE-2026-19710SourceCodester Simple Student Information System view_department.php sql injectionSimple Student Information System5.5 (v4.0)Medium
CVE-2026-19899SourceCodester Class and Exam Timetabling System edit_teacher.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-19919code-projects Online Shopping System Login login.php sql injectionOnline Shopping System5.5 (v4.0)Medium
CVE-2026-19926Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injectionEvergreen5.5 (v4.0)Medium
CVE-2026-45376Decidim: Admin user search allows SQL injection through similarity-based sortingdecidim5.5 (v3.1)Medium
CVE-2026-5368projectworlds Car Rental Project Parameter login.php sql injectioncar rental project5.5 (v4.0)Medium
CVE-2026-5551itsourcecode Free Hotel Reservation System Parameter login.php sql injectionFree Hotel Reservation System5.5 (v4.0)Medium
CVE-2026-5554code-projects Concert Ticket Reservation System Parameter process_search.php sql injectionConcert Ticket Reservation System5.5 (v4.0)Medium
CVE-2026-5555code-projects Concert Ticket Reservation System Parameter login.php sql injectionConcert Ticket Reservation System5.5 (v4.0)Medium
CVE-2026-5564code-projects Simple Laundry System Parameter searchguest.php sql injectionSimple Laundry System5.5 (v4.0)Medium
CVE-2026-5565code-projects Simple Laundry System Parameter delmemberinfo.php sql injectionSimple Laundry System5.5 (v4.0)Medium
CVE-2026-5575SourceCodester/jkev Record Management System Login index.php sql injectionRecord Management System5.5 (v4.0)Medium
CVE-2026-5577Song-Li cross_browser details Endpoint uniquemachine_app.py sql injectioncross browser fingerprinting5.5 (v4.0)Medium
CVE-2026-5634projectworlds Car Rental Project Parameter book_car.php sql injectionCar Rental Project5.5 (v4.0)Medium
CVE-2026-5672code-projects Simple IT Discussion Forum Parameter edit-category.php sql injectionSimple IT Discussion Forum5.5 (v4.0)Medium
CVE-2026-5805code-projects Easy Blog Site contact_us.php sql injectionEasy Blog Site5.5 (v4.0)Medium
CVE-2026-5813PHPGurukul Online Course Registration check_availability.php sql injectionOnline Course Registration5.5 (v4.0)Medium
CVE-2026-5814PHPGurukul Online Course Registration check_availability.php sql injectionOnline Course Registration5.5 (v4.0)Medium
CVE-2026-5824code-projects Simple Laundry System userchecklogin.php sql injectionSimple Laundry System5.5 (v4.0)Medium
CVE-2026-5829code-projects Simple IT Discussion Forum content.php sql injectionSimple IT Discussion Forum5.5 (v4.0)Medium
CVE-2026-7194SourceCodester Pharmacy Sales and Inventory System ajax.php sql injectionPharmacy Sales and Inventory System5.5 (v4.0)Medium
CVE-2026-75014SourceCodester Pet Grooming Management Software get_barcode_data.php sql injectionPet Grooming Management Software5.5 (v4.0)Medium
CVE-2026-75079SourceCodester Class and Exam Timetabling System edit_subject2.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-75080SourceCodester Class and Exam Timetabling System edit_subject1.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-75089PHPGurukul Complaint Management System check_availability.php sql injectionComplaint Management System5.5 (v4.0)Medium
CVE-2026-75778code-projects Task Management System Login Form index.php select_with_multiple_condition sql injectionTask Management System5.5 (v4.0)Medium
CVE-2026-75986code-projects Online Job Portal System Password Recovery ForPass.php sql injectionOnline Job Portal System5.5 (v4.0)Medium
CVE-2026-76048SourceCodester Simple Online Food Ordering System ajax.php login sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-76049SourceCodester Simple Online Food Ordering System ajax.php save_menu sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-76574code-projects Hospital Information System User Login UsersController.php login sql injectionHospital Information System5.5 (v4.0)Medium
CVE-2026-76762code-projects Assessment Management welcome.php sql injectionAssessment Management5.5 (v4.0)Medium
CVE-2026-76764code-projects Employee Management System Admin Login Endpoint aprocess.php sql injectionEmployee Management System5.5 (v4.0)Medium
CVE-2026-76990code-projects Simple Inventory System delete.php sql injectionSimple Inventory System5.5 (v4.0)Medium
CVE-2026-76996SourceCodester Simple Online Food Ordering System view_order.php sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-76998SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-77019CodeAstro Apartment Visitor Management System forgotpw.php sql injectionApartment Visitor Management System5.5 (v4.0)Medium
CVE-2026-77020CodeAstro Apartment Visitor Management System password-recovery.php sql injectionApartment Visitor Management System5.5 (v4.0)Medium
CVE-2026-78143code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injectionBarangay Resident Profiling Management System5.5 (v4.0)Medium
CVE-2026-78171itsourcecode Sales and Inventory System processlogin.php sql injectionSales and Inventory System5.5 (v4.0)Medium
CVE-2026-78197SourceCodester Simple Online Food Ordering System ajax.php save_user sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-78198SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-78199SourceCodester Simple Online Food Ordering System view_prod.php sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-78201itsourcecode Payroll System admin_class.php login sql injectionPayroll System5.5 (v4.0)Medium
CVE-2026-78244itsourcecode Real Estate Management System search.php sql injectionReal Estate Management System5.5 (v4.0)Medium
CVE-2026-78246itsourcecode Online Clinic Management System Admin Login login.php sql injectionOnline Clinic Management System5.5 (v4.0)Medium
CVE-2026-78247SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-78248SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-79804SililaWijesinghe Food Ordering System search.php sql injectionFood Ordering System5.5 (v4.0)Medium
CVE-2026-79845code-projects Simple Inventory System edit.php sql injectionSimple Inventory System5.5 (v4.0)Medium
CVE-2026-81203SourceCodester Simple Online Food Ordering System ajax.php login2 sql injectionSimple Online Food Ordering System5.5 (v4.0)Medium
CVE-2026-82600SeaCMS zyapi.php sql injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-82610itsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium
CVE-2026-82611itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium
CVE-2026-82612itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium
CVE-2026-82613itsourcecode Online Medicine Delivery System Product Search index.php loadResultList sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium
CVE-2026-82614itsourcecode Online Medicine Delivery System Product Category Filter index.php loadResultList sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium
CVE-2026-82615itsourcecode Online Medicine Delivery System Password Recovery passwordrecover.php find_phone sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium
CVE-2026-82701code-projects Online Shopping System Search Functionality action.php sql injectionOnline Shopping System5.5 (v4.0)Medium
CVE-2026-84111Chanjet CRM jxf_dump_table.php sql injectionCRM5.5 (v4.0)Medium
CVE-2026-85187itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injectionOnline Medicine Delivery System5.5 (v4.0)Medium
CVE-2026-85225code-projects Doctor Appointment System patient_login.php sql injectionDoctor Appointment System5.5 (v4.0)Medium
CVE-2026-85379light0011 cms Query Builder ChapterController.class.php searchChapter sql injectioncms5.5 (v4.0)Medium
CVE-2026-85397code-projects Hospital Information System addReq.php findBySearch sql injectionHospital Information System5.5 (v4.0)Medium
CVE-2026-85398code-projects Hospital Information System viewReq.php viewReq sql injectionHospital Information System5.5 (v4.0)Medium
CVE-2026-85399code-projects Hospital Information System PrespController.php getSinglePresp sql injectionHospital Information System5.5 (v4.0)Medium
CVE-2026-85402code-projects Doctor Appointment System booking.php sql injectionDoctor Appointment System5.5 (v4.0)Medium
CVE-2026-85403code-projects Doctor Appointment System contactus.php sql injectionDoctor Appointment System5.5 (v4.0)Medium
CVE-2026-85512SourceCodester Class and Exam Timetabling System session.php authorizationClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-85516code-projects Vehicle Management System busprofile.php sql injectionVehicle Management System5.5 (v4.0)Medium
CVE-2026-86159SourceCodester Online Voting System ajax.php save_user sql injectionOnline Voting System5.5 (v4.0)Medium
CVE-2026-86160SourceCodester Online Voting System ajax.php delete_voting sql injectionOnline Voting System5.5 (v4.0)Medium
CVE-2026-86161SourceCodester Online Voting System ajax.php delete_category sql injectionOnline Voting System5.5 (v4.0)Medium
CVE-2026-86162SourceCodester Online Voting System ajax.php login sql injectionOnline Voting System5.5 (v4.0)Medium
CVE-2026-86168code-projects Content Management System login.php sql injectionContent Management System5.5 (v4.0)Medium
CVE-2026-86180code-projects Task Management System In PHP Login index.php sql injectionTask Management System In PHP5.5 (v4.0)Medium
CVE-2026-86208SourceCodester Class and Exam Timetabling System delete_teacher.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86209SourceCodester Class and Exam Timetabling System delete_user.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86210SourceCodester Class and Exam Timetabling System delete_user_account.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86211rabindralamsal inventory-management-system Login index.php sql injectioninventory-management-system5.5 (v4.0)Medium
CVE-2026-86213Mstfakts College-Management-System Search university.php mysqli_query sql injectionCollege-Management-System5.5 (v4.0)Medium
CVE-2026-86220SourceCodester Class and Exam Timetabling System modal_add_course.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86221SourceCodester Class and Exam Timetabling System modal_add_course1.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86222SourceCodester Class and Exam Timetabling System modal_add_course2.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86223SourceCodester Class and Exam Timetabling System modal_add_coursea.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86224SourceCodester Class and Exam Timetabling System modal_add_product.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86225SourceCodester Class and Exam Timetabling System modal_add_room.php mysqli_query sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-86268itsourcecode School Management System User_Login.php sql injectionSchool Management System5.5 (v4.0)Medium
CVE-2026-86290SourceCodester Online Voting System ajax.php save_category sql injectionOnline Voting System5.5 (v4.0)Medium
CVE-2026-86298SourceCodester Class and Exam Timetabling System delete_subject.php sql injectionClass and Exam Timetabling System5.5 (v4.0)Medium
CVE-2026-9355SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injectionHospitals Patient Records Management System5.5 (v4.0)Medium
CVE-2026-9356SourceCodester Hospitals Patient Records Management System manage_history.php sql injectionHospitals Patient Records Management System5.5 (v4.0)Medium
CVE-2026-9364projectworlds Online Art Gallery Shop adminHome.php sql injectionOnline Art Gallery Shop5.5 (v4.0)Medium
CVE-2026-9383itsourcecode Electronic Judging System login.php sql injectionElectronic Judging System5.5 (v4.0)Medium
CVE-2026-9469yashpokharna2555 StudentManagementSystem success.php sql injectionStudentManagementSystem5.5 (v4.0)Medium
CVE-2026-9470yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium
CVE-2026-9525itsourcecode Electronic Judging System edit_judge.php sql injectionElectronic Judging System5.5 (v4.0)Medium
CVE-2026-9526itsourcecode Electronic Judging System edit_team.php sql injectionElectronic Judging System5.5 (v4.0)Medium
CVE-2026-9528itsourcecode Electronic Judging System delete_judge.php sql injectionElectronic Judging System5.5 (v4.0)Medium
CVE-2026-9573itsourcecode Student Transcript Processing System index.php sql injectionStudent Transcript Processing System5.5 (v4.0)Medium
CVE-2026-9574itsourcecode Student Transcript Processing System trans.php sql injectionStudent Transcript Processing System5.5 (v4.0)Medium
CVE-2026-9575itsourcecode Student Transcript Processing System index.php sql injectionStudent Transcript Processing System5.5 (v4.0)Medium
CVE-2026-9584code-projects Project Management System Login chk.php sql injectionProject Management System5.5 (v4.0)Medium
CVE-2026-9606itsourcecode Courier Management System manage_user.php sql injectionCourier Management System5.5 (v4.0)Medium
CVE-2023-6030LogDash Activity Log <= 1.1.3 - SQL Injectionlogdash activity log5.4 (v3.1)Medium
CVE-2026-26378koha Arbitrary Code Execution Vulnerabilitykoha5.4 (v3.1)Medium
CVE-2026-30520loan management system SQL Injection Vulnerabilityloan management system5.4 (v3.1)Medium
CVE-2026-38467the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerabilitythe tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d184464495.4 (v3.1)Medium
CVE-2026-47720FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeTdStringFUXA5.3 (v3.1)Medium
CVE-2026-5606PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injectionOnline Shopping Portal Project5.3 (v4.0)Medium
CVE-2026-78864liketrek TREK Journey Entry Update journey.controller.t journeyService.updateEntry sql injectionTREK5.3 (v4.0)Medium
CVE-2026-85205itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injectionOnline Medicine Delivery System5.3 (v4.0)Medium
CVE-2026-9524xianrendzw EasyReport REST Endpoint execute sql injectionEasyReport5.3 (v4.0)Medium
CVE-2018-1002001WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2018-1002002WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2018-1002003WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2018-1002004WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2018-1002005WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2018-1002006WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2018-1002007WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2018-1002008WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2018-1002009WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scriptingarigato autoresponder and newsletter4.8 (v3.0)Medium
CVE-2014-9146Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms4.3 (v2.0)Medium
CVE-2026-38468the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 SQL Injection Vulnerabilitythe country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d184464494.3 (v3.1)Medium
CVE-2026-72610Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip GenerationKoha4.3 (v3.1)Medium
CVE-2026-14238Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-reportvitepos4.1 (v3.1)Medium
CVE-2014-1222Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesvtiger crm4.0 (v2.0)Medium
CVE-2026-14189WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fieldsWPBot3.8 (v3.1)Low
CVE-2026-15381WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filterWP Go Maps3.7 (v3.1)Low
CVE-2025-10592itsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injectiononline public access catalog2.1 (v4.0)Low
CVE-2025-13811jsnjfz WebStack-Guns PageFactory.java sql injectionwebstack-guns2.1 (v4.0)Low
CVE-2026-10170code-projects Visitor Management System phone_0.php sql injectionVisitor Management System2.1 (v4.0)Low
CVE-2026-10193OFCMS ComnController ComnController.java query sql injectionOFCMS2.1 (v4.0)Low
CVE-2026-10202OFCMS JSON Query SystemDictController.java query sql injectionOFCMS2.1 (v4.0)Low
CVE-2026-10203OFCMS JSON Query SystemParamController.java query sql injectionOFCMS2.1 (v4.0)Low
CVE-2026-10204OFCMS JSON Query SysUserController.java query sql injectionOFCMS2.1 (v4.0)Low
CVE-2026-10209code-projects Online Hospital Management System Appointment appointmentdetail.php sql injectionOnline Hospital Management System2.1 (v4.0)Low
CVE-2026-10256itsourcecode Content Management System save_comment.php sql injectionContent Management System2.1 (v4.0)Low
CVE-2026-10258itsourcecode Content Management System add_sub_topic.php sql injectionContent Management System2.1 (v4.0)Low
CVE-2026-10265itsourcecode Content Management System edit_topic.php sql injectionContent Management System2.1 (v4.0)Low
CVE-2026-10286CodeAstro Payroll System home_employee.php sql injectionPayroll System2.1 (v4.0)Low
CVE-2026-10296itsourcecode Fees Management System ajax.php sql injectionFees Management System2.1 (v4.0)Low
CVE-2026-10297itsourcecode Fees Management System manage_course.php sql injectionFees Management System2.1 (v4.0)Low
CVE-2026-10302itsourcecode Fees Management System manage_fee.php sql injectionFees Management System2.1 (v4.0)Low
CVE-2026-10568itsourcecode Fees Management System manage_payment.php sql injectionFees Management System2.1 (v4.0)Low
CVE-2026-10808itsourcecode Fees Management System manage_student.php sql injectionFees Management System2.1 (v4.0)Low
CVE-2026-10809itsourcecode Fees Management System manage_user.php sql injectionFees Management System2.1 (v4.0)Low
CVE-2026-10811itsourcecode Fees Management System receipt.php sql injectionFees Management System2.1 (v4.0)Low
CVE-2026-10874projectworlds Online Art Gallery Shop Project adminHome.php sql injectionOnline Art Gallery Shop Project2.1 (v4.0)Low
CVE-2026-10875projectworlds Online Art Gallery Shop Project adminHome.ph sql injectionOnline Art Gallery Shop Project2.1 (v4.0)Low
CVE-2026-11412Jinher OA GetFormSn.aspx sql injectionOA2.1 (v4.0)Low
CVE-2026-11475Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injectionstudent-management-system2.1 (v4.0)Low
CVE-2026-11476Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorizationstudent-management-system2.1 (v4.0)Low
CVE-2026-11495CodeAstro Ingredients Stock Management System add_stock.php sql injectionIngredients Stock Management System2.1 (v4.0)Low
CVE-2026-11506CodeAstro Leave Management System search_staff_for_deletion.php sql injectionLeave Management System2.1 (v4.0)Low
CVE-2026-11507CodeAstro Leave Management System delete_leave_type.php sql injectionLeave Management System2.1 (v4.0)Low
CVE-2026-11508CodeAstro Leave Management System search_staff_to_assign_pc.php sql injectionLeave Management System2.1 (v4.0)Low
CVE-2026-11510CodeAstro Leave Management System add_leave.php sql injectionLeave Management System2.1 (v4.0)Low
CVE-2026-11513itsourcecode Hospital Management System adminaccount.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-11514itsourcecode Hospital Management System addpatient.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-11529designcomputer mysql-mcp-server mysql URI server.py read_resource sql injectionmysql-mcp-server2.1 (v4.0)Low
CVE-2026-11558CodeAstro Payroll System home_salary.php sql injectionPayroll System2.1 (v4.0)Low
CVE-2026-11559CodeAstro Payroll System view_account.php sql injectionPayroll System2.1 (v4.0)Low
CVE-2026-11583CodeAstro Student Attendance Management System createClass.php sql injectionStudent Attendance Management System2.1 (v4.0)Low
CVE-2026-11584CodeAstro Student Attendance Management System createClass.php edit sql injectionStudent Attendance Management System2.1 (v4.0)Low
CVE-2026-11585CodeAstro Student Attendance Management System createClassArms.php sql injectionStudent Attendance Management System2.1 (v4.0)Low
CVE-2026-16131itsourcecode Hospital Management System prescriptionrecord.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-16244itsourcecode Hospital Management System prescriptionorderreport.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-16334itsourcecode Hospital Management System prescriptionorder.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-16449zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injectionZS-Admin2.1 (v4.0)Low
CVE-2026-18766chetans9 core-php-admin-panel customers.php sql injectioncore-php-admin-panel2.1 (v4.0)Low
CVE-2026-18896lavkush-maurya Student-Registration-System changepass.php sql injectionStudent-Registration-System2.1 (v4.0)Low
CVE-2026-19020itsourcecode Hospital Management System servicetype.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19067itsourcecode Hospital Management System treatment.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19068itsourcecode Hospital Management System treatmentdetail.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19069itsourcecode Hospital Management System treatmentrecord.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19070itsourcecode Hospital Management System viewadmin.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19071itsourcecode Hospital Management System viewappointment.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19347itsourcecode Hospital Management System viewdoctor.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19364itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19767itsourcecode Hospital Management System viewdoctortimings.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19894itsourcecode Hospital Management System viewmedicine.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19917code-projects Online Food Order System delete_food_items1.php sql injectionOnline Food Order System2.1 (v4.0)Low
CVE-2026-19920code-projects Online Shopping System action.php sql injectionOnline Shopping System2.1 (v4.0)Low
CVE-2026-19921code-projects Online Shopping System homeaction.php sql injectionOnline Shopping System2.1 (v4.0)Low
CVE-2026-19923code-projects Online Shopping System checkout_process.php sql injectionOnline Shopping System2.1 (v4.0)Low
CVE-2026-19934itsourcecode Hospital Management System vieworder.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19972itsourcecode Hospital Management System viewpatient.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-19973itsourcecode Hospital Management System viewpaymentreport.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-20000itsourcecode Hospital Management System viewprescriptionrecord.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-5206code-projects Simple Gym Management System Payment sql injectionSimple Gym Management System2.1 (v4.0)Low
CVE-2026-5537halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injectionCourseSEL2.1 (v4.0)Low
CVE-2026-5543PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injectionUser Registration & Login and User Management System2.1 (v4.0)Low
CVE-2026-5552PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low
CVE-2026-5553itsourcecode Online Cellphone System Parameter available.php sql injectionOnline Cellphone System2.1 (v4.0)Low
CVE-2026-5558PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injectionPHPGurukul Online Shopping Portal Project2.1 (v4.0)Low
CVE-2026-5560PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low
CVE-2026-5578CodeAstro Online Classroom Parameter addassessment.php sql injectionOnline Classroom2.1 (v4.0)Low
CVE-2026-5579CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injectionOnline Classroom2.1 (v4.0)Low
CVE-2026-5580CodeAstro Online Classroom Parameter addvideos.php sql injectionOnline Classroom2.1 (v4.0)Low
CVE-2026-5583PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low
CVE-2026-5620itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injectionConstruction Management System2.1 (v4.0)Low
CVE-2026-5635PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low
CVE-2026-5636PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injectionOnline Shopping Portal Project2.1 (v4.0)Low
CVE-2026-5675itsourcecode Construction Management System Parameter borrowed_tool.php sql injectionConstruction Management System2.1 (v4.0)Low
CVE-2026-5681itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injectionsanitize or validate this input2.1 (v4.0)Low
CVE-2026-5719itsourcecode Construction Management System borrowedtool.php sql injectionConstruction Management System2.1 (v4.0)Low
CVE-2026-5823itsourcecode Construction Management System borrowed_tool_report.php sql injectionConstruction Management System2.1 (v4.0)Low
CVE-2026-7196CodeAstro Online Classroom guestdetails sql injectionOnline Classroom2.1 (v4.0)Low
CVE-2026-75086itsourcecode Hospital Management System viewroom.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-75087itsourcecode Hospital Management System viewdepartment.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-75088itsourcecode Hospital Management System viewbilling.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-75876xianrendzw EasyReport Move Operations ModuleController.java sql injectionEasyReport2.1 (v4.0)Low
CVE-2026-76785amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injectionMini-Inventory-and-Sales-Management-System2.1 (v4.0)Low
CVE-2026-76991itsourcecode Hospital Management System viewappointmentapproved.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-76997SourceCodester Simple Online Food Ordering System ajax.php save_category sql injectionSimple Online Food Ordering System2.1 (v4.0)Low
CVE-2026-77025itsourcecode Hospital Management System viewappointmentpending.php sql injectionHospital Management System2.1 (v4.0)Low
CVE-2026-78056sambitraj Student-Management-System Dashboard sql injectionStudent-Management-System2.1 (v4.0)Low
CVE-2026-78057sambitraj Student-Management-System Management Mutation sql injectionStudent-Management-System2.1 (v4.0)Low
CVE-2026-78112itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injectionHospital Management System Project in PHP2.1 (v4.0)Low
CVE-2026-78185itsourcecode Sales and Inventory System cust_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-78200itsourcecode Library Management System editbooks.php sql injectionLibrary Management System2.1 (v4.0)Low
CVE-2026-78656itsourcecode Sales and Inventory System cust_del.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-8231CodeAstro Online Catering Ordering System deleteorder.php sql injectionOnline Catering Ordering System2.1 (v4.0)Low
CVE-2026-82421itsourcecode Sales and Inventory System emp_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-82422itsourcecode Sales and Inventory System emp_del.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-82424PHPGurukul Student Information System student_edit1.php sql injectionStudent Information System2.1 (v4.0)Low
CVE-2026-82484itsourcecode Sales and Inventory System emp_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-82485itsourcecode Sales and Inventory System pro_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-82540itsourcecode Sales and Inventory System cust_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-82541itsourcecode Sales and Inventory System sup_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-82545itsourcecode Sales and Inventory System sup_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-82609itsourcecode Sales and Inventory System inv_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-82696itsourcecode Sales and Inventory System inv_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-84109Xinhu Rainrock RockOA webmainAction.php getOrder sql injectionRainrock RockOA2.1 (v4.0)Low
CVE-2026-84153Xinhu Rainrock RockOA index.php toaddval sql injectionRainrock RockOA2.1 (v4.0)Low
CVE-2026-85383itsourcecode Sales and Inventory System inv_del.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86163itsourcecode Sales and Inventory System pro_del.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86164itsourcecode Sales and Inventory System trans_view.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86170DefaultFuction CRM edit.php sql injectionCRM2.1 (v4.0)Low
CVE-2026-86171DefaultFuction CRM delete.php sql injectionCRM2.1 (v4.0)Low
CVE-2026-86172DefaultFuction CRM delete.php sql injectionCRM2.1 (v4.0)Low
CVE-2026-86232itsourcecode Sales and Inventory System sup_del.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86233itsourcecode Sales and Inventory System us_del.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86234itsourcecode Sales and Inventory System cust_transac.php add sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86235itsourcecode Sales and Inventory System pos_transac.php add sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86236itsourcecode Sales and Inventory System pro_transac.php add sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86245itsourcecode Sales and Inventory System sup_transac.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86265itsourcecode Sales and Inventory System us_transac.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86267itsourcecode Information System Society Membership System check_student.php sql injectionInformation System Society Membership System2.1 (v4.0)Low
CVE-2026-86269itsourcecode Sales and Inventory System emp_edit1.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86270itsourcecode Sales and Inventory System settings_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86291itsourcecode Sales and Inventory System us_edit1.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86309itsourcecode Sales and Inventory System pro_searchfrm.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86310itsourcecode Sales and Inventory System cust_edit1.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86517itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-86518code-projects Student Crud Operation edit.php sql injectionStudent Crud Operation2.1 (v4.0)Low
CVE-2026-86675itsourcecode Sales and Inventory System us_edit.php sql injectionSales and Inventory System2.1 (v4.0)Low
CVE-2026-9342SourceCodester Hospitals Patient Records Management System view_history.php sql injectionHospitals Patient Records Management System2.1 (v4.0)Low
CVE-2026-9450code-projects Employee Management System psubmit.php sql injectionEmployee Management System2.1 (v4.0)Low
CVE-2026-9451code-projects Employee Management System applyleaveprocess.php sql injectionEmployee Management System2.1 (v4.0)Low
CVE-2026-9542CodeAstro Leave Management System add_staff.php sql injectionLeave Management System2.1 (v4.0)Low
CVE-2026-9607itsourcecode Courier Management System parcel_list.php sql injectionCourier Management System2.1 (v4.0)Low
CVE-2026-10155Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injectionMulti-Store Inventory Management System2.0 (v4.0)Low
CVE-2026-10171code-projects Online Music Site AdminUpdateAlbum.php sql injectionOnline Music Site2.0 (v4.0)Low
CVE-2026-19787SourceCodester Air Cargo Management System Master.php save_cargo_type sql injectionAir Cargo Management System2.0 (v4.0)Low
CVE-2026-19925SourceCodester Stock Management System Master.php delete_supplier sql injectionStock Management System2.0 (v4.0)Low
CVE-2026-85643code-projects Online Shopping System adduser.php mysqli_query sql injectionOnline Shopping System2.0 (v4.0)Low
CVE-2026-86667aircheng-org iWebShop-5 member.php member_list sql injectioniWebShop-52.0 (v4.0)Low
CVE-2022-43128Dreamer CMS v4.0.0 - SQL Injection-N/AN/A
CVE-2026-38626Garlic-Hub v1.0.1 SQL Injection Vulnerability-N/AN/A

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2014-1222
CWE-74CVE-2025-6403 , CVE-2026-10178 , CVE-2026-10186 , CVE-2026-10249 , CVE-2026-10250 , CVE-2026-10251 , CVE-2026-10252 , CVE-2026-10253 , CVE-2026-10260 , CVE-2026-10261 , CVE-2026-10262 , CVE-2026-10263 , CVE-2026-10620 , CVE-2026-10704 , CVE-2026-11435 , CVE-2026-11456 , CVE-2026-11482 , CVE-2026-11483 , CVE-2026-11484 , CVE-2026-11485 , CVE-2026-11486 , CVE-2026-11488 , CVE-2026-11489 , CVE-2026-11490 , CVE-2026-11501 , CVE-2026-11582 , CVE-2026-16152 , CVE-2026-16154 , CVE-2026-16227 , CVE-2026-16228 , CVE-2026-16484 , CVE-2026-16765 , CVE-2026-19021 , CVE-2026-19196 , CVE-2026-19211 , CVE-2026-19343 , CVE-2026-19344 , CVE-2026-19384 , CVE-2026-19710 , CVE-2026-19899 , CVE-2026-19919 , CVE-2026-19926 , CVE-2026-5368 , CVE-2026-5551 , CVE-2026-5554 , CVE-2026-5555 , CVE-2026-5564 , CVE-2026-5565 , CVE-2026-5575 , CVE-2026-5577 , CVE-2026-5634 , CVE-2026-5672 , CVE-2026-5805 , CVE-2026-5813 , CVE-2026-5814 , CVE-2026-5824 , CVE-2026-5829 , CVE-2026-7194 , CVE-2026-75014 , CVE-2026-75079 , CVE-2026-75080 , CVE-2026-75089 , CVE-2026-75778 , CVE-2026-75986 , CVE-2026-76048 , CVE-2026-76049 , CVE-2026-76574 , CVE-2026-76762 , CVE-2026-76764 , CVE-2026-76990 , CVE-2026-76996 , CVE-2026-76998 , CVE-2026-77019 , CVE-2026-77020 , CVE-2026-78143 , CVE-2026-78171 , CVE-2026-78197 , CVE-2026-78198 , CVE-2026-78199 , CVE-2026-78201 , CVE-2026-78244 , CVE-2026-78246 , CVE-2026-78247 , CVE-2026-78248 , CVE-2026-79804 , CVE-2026-79845 , CVE-2026-81203 , CVE-2026-82600 , CVE-2026-82610 , CVE-2026-82611 , CVE-2026-82612 , CVE-2026-82613 , CVE-2026-82614 , CVE-2026-82615 , CVE-2026-82701 , CVE-2026-84111 , CVE-2026-85187 , CVE-2026-85225 , CVE-2026-85379 , CVE-2026-85397 , CVE-2026-85398 , CVE-2026-85399 , CVE-2026-85402 , CVE-2026-85403 , CVE-2026-85516 , CVE-2026-86159 , CVE-2026-86160 , CVE-2026-86161 , CVE-2026-86162 , CVE-2026-86168 , CVE-2026-86180 , CVE-2026-86208 , CVE-2026-86209 , CVE-2026-86210 , CVE-2026-86211 , CVE-2026-86213 , CVE-2026-86220 , CVE-2026-86221 , CVE-2026-86222 , CVE-2026-86223 , CVE-2026-86224 , CVE-2026-86225 , CVE-2026-86268 , CVE-2026-86290 , CVE-2026-86298 , CVE-2026-9355 , CVE-2026-9356 , CVE-2026-9364 , CVE-2026-9383 , CVE-2026-9469 , CVE-2026-9470 , CVE-2026-9525 , CVE-2026-9526 , CVE-2026-9528 , CVE-2026-9573 , CVE-2026-9574 , CVE-2026-9575 , CVE-2026-9584 , CVE-2026-9606 , CVE-2026-5606 , CVE-2026-78864 , CVE-2026-85205 , CVE-2026-9524 , CVE-2025-10592 , CVE-2025-13811 , CVE-2026-10170 , CVE-2026-10193 , CVE-2026-10202 , CVE-2026-10203 , CVE-2026-10204 , CVE-2026-10209 , CVE-2026-10256 , CVE-2026-10258 , CVE-2026-10265 , CVE-2026-10286 , CVE-2026-10296 , CVE-2026-10297 , CVE-2026-10302 , CVE-2026-10568 , CVE-2026-10808 , CVE-2026-10809 , CVE-2026-10811 , CVE-2026-10874 , CVE-2026-10875 , CVE-2026-11412 , CVE-2026-11475 , CVE-2026-11495 , CVE-2026-11506 , CVE-2026-11507 , CVE-2026-11508 , CVE-2026-11510 , CVE-2026-11513 , CVE-2026-11514 , CVE-2026-11529 , CVE-2026-11558 , CVE-2026-11559 , CVE-2026-11583 , CVE-2026-11584 , CVE-2026-11585 , CVE-2026-16131 , CVE-2026-16244 , CVE-2026-16334 , CVE-2026-16449 , CVE-2026-18766 , CVE-2026-18896 , CVE-2026-19020 , CVE-2026-19067 , CVE-2026-19068 , CVE-2026-19069 , CVE-2026-19070 , CVE-2026-19071 , CVE-2026-19347 , CVE-2026-19364 , CVE-2026-19767 , CVE-2026-19894 , CVE-2026-19917 , CVE-2026-19920 , CVE-2026-19921 , CVE-2026-19923 , CVE-2026-19934 , CVE-2026-19972 , CVE-2026-19973 , CVE-2026-20000 , CVE-2026-5206 , CVE-2026-5537 , CVE-2026-5543 , CVE-2026-5552 , CVE-2026-5553 , CVE-2026-5558 , CVE-2026-5560 , CVE-2026-5578 , CVE-2026-5579 , CVE-2026-5580 , CVE-2026-5583 , CVE-2026-5620 , CVE-2026-5635 , CVE-2026-5636 , CVE-2026-5675 , CVE-2026-5681 , CVE-2026-5719 , CVE-2026-5823 , CVE-2026-7196 , CVE-2026-75086 , CVE-2026-75087 , CVE-2026-75088 , CVE-2026-75876 , CVE-2026-76785 , CVE-2026-76991 , CVE-2026-76997 , CVE-2026-77025 , CVE-2026-78056 , CVE-2026-78057 , CVE-2026-78112 , CVE-2026-78185 , CVE-2026-78200 , CVE-2026-78656 , CVE-2026-8231 , CVE-2026-82421 , CVE-2026-82422 , CVE-2026-82424 , CVE-2026-82484 , CVE-2026-82485 , CVE-2026-82540 , CVE-2026-82541 , CVE-2026-82545 , CVE-2026-82609 , CVE-2026-82696 , CVE-2026-84109 , CVE-2026-84153 , CVE-2026-85383 , CVE-2026-86163 , CVE-2026-86164 , CVE-2026-86170 , CVE-2026-86171 , CVE-2026-86172 , CVE-2026-86232 , CVE-2026-86233 , CVE-2026-86234 , CVE-2026-86235 , CVE-2026-86236 , CVE-2026-86245 , CVE-2026-86265 , CVE-2026-86267 , CVE-2026-86269 , CVE-2026-86270 , CVE-2026-86291 , CVE-2026-86309 , CVE-2026-86310 , CVE-2026-86517 , CVE-2026-86518 , CVE-2026-86675 , CVE-2026-9342 , CVE-2026-9450 , CVE-2026-9451 , CVE-2026-9542 , CVE-2026-9607 , CVE-2026-10155 , CVE-2026-10171 , CVE-2026-19787 , CVE-2026-19925 , CVE-2026-85643 , CVE-2026-86667
CWE-79CVE-2026-26378 , CVE-2018-1002001 , CVE-2018-1002002 , CVE-2018-1002003 , CVE-2018-1002004 , CVE-2018-1002005 , CVE-2018-1002006 , CVE-2018-1002007 , CVE-2018-1002008 , CVE-2018-1002009 , CVE-2014-9146
CWE-89CVE-2024-30498 , CVE-2026-72899 , CVE-2024-51482 , CVE-2026-51366 , CVE-2026-69083 , CVE-2026-69084 , CVE-2026-69085 , CVE-2015-3934 , CVE-2015-9323 , CVE-2017-17970 , CVE-2017-17999 , CVE-2017-9834 , CVE-2018-11511 , CVE-2018-16159 , CVE-2018-18923 , CVE-2018-7538 , CVE-2020-11530 , CVE-2020-17463 , CVE-2020-18662 , CVE-2020-27481 , CVE-2020-27615 , CVE-2020-35545 , CVE-2020-8656 , CVE-2021-24139 , CVE-2021-24442 , CVE-2021-24731 , CVE-2021-24762 , CVE-2021-24827 , CVE-2021-24849 , CVE-2021-24931 , CVE-2021-24943 , CVE-2021-24946 , CVE-2021-25114 , CVE-2021-26599 , CVE-2021-27314 , CVE-2021-3018 , CVE-2021-3110 , CVE-2022-0349 , CVE-2022-0412 , CVE-2022-0592 , CVE-2022-0658 , CVE-2022-0693 , CVE-2022-0747 , CVE-2022-0760 , CVE-2022-0769 , CVE-2022-0773 , CVE-2022-0783 , CVE-2022-0784 , CVE-2022-0785 , CVE-2022-0786 , CVE-2022-0787 , CVE-2022-0788 , CVE-2022-0826 , CVE-2022-0827 , CVE-2022-0846 , CVE-2022-0867 , CVE-2022-0948 , CVE-2022-0949 , CVE-2022-1013 , CVE-2022-1057 , CVE-2022-1950 , CVE-2022-22897 , CVE-2022-24223 , CVE-2022-2467 , CVE-2022-27984 , CVE-2022-28032 , CVE-2022-28033 , CVE-2022-2840 , CVE-2022-31340 , CVE-2022-31976 , CVE-2022-31977 , CVE-2022-31978 , CVE-2022-33965 , CVE-2022-3481 , CVE-2022-40032 , CVE-2022-4059 , CVE-2022-44290 , CVE-2022-44291 , CVE-2022-44588 , CVE-2022-45805 , CVE-2022-45808 , CVE-2023-0600 , CVE-2023-1730 , CVE-2023-2130 , CVE-2023-23488 , CVE-2023-23489 , CVE-2023-24000 , CVE-2023-27034 , CVE-2023-27637 , CVE-2023-27638 , CVE-2023-27847 , CVE-2023-30150 , CVE-2023-30192 , CVE-2023-3197 , CVE-2023-34751 , CVE-2023-34752 , CVE-2023-34753 , CVE-2023-34754 , CVE-2023-34755 , CVE-2023-34756 , CVE-2023-39361 , CVE-2023-39650 , CVE-2023-39796 , CVE-2023-43373 , CVE-2023-43374 , CVE-2023-48084 , CVE-2023-4974 , CVE-2023-50839 , CVE-2023-5652 , CVE-2023-6360 , CVE-2024-1061 , CVE-2024-1512 , CVE-2024-1698 , CVE-2024-24495 , CVE-2024-2621 , CVE-2024-27956 , CVE-2024-2876 , CVE-2024-30490 , CVE-2024-30502 , CVE-2024-3552 , CVE-2024-3605 , CVE-2024-36412 , CVE-2024-38773 , CVE-2024-43144 , CVE-2024-43360 , CVE-2024-43917 , CVE-2024-43965 , CVE-2024-5057 , CVE-2024-51211 , CVE-2024-5765 , CVE-2024-6159 , CVE-2024-6205 , CVE-2024-6265 , CVE-2024-6924 , CVE-2024-6926 , CVE-2024-6928 , CVE-2024-7854 , CVE-2024-8911 , CVE-2025-24799 , CVE-2025-57631 , CVE-2025-65336 , CVE-2025-65340 , CVE-2025-67066 , CVE-2025-67403 , CVE-2025-67404 , CVE-2025-69930 , CVE-2025-69931 , CVE-2025-69933 , CVE-2025-69934 , CVE-2025-69935 , CVE-2025-69936 , CVE-2025-69937 , CVE-2025-69938 , CVE-2025-69941 , CVE-2025-69942 , CVE-2025-69943 , CVE-2025-69946 , CVE-2025-69947 , CVE-2025-69948 , CVE-2025-70149 , CVE-2025-70152 , CVE-2026-10880 , CVE-2026-21875 , CVE-2026-46670 , CVE-2026-48528 , CVE-2026-51775 , CVE-2026-52348 , CVE-2026-52472 , CVE-2026-67689 , CVE-2026-68000 , CVE-2026-69240 , CVE-2026-75330 , CVE-2026-75336 , CVE-2026-79569 , CVE-2026-79570 , CVE-2019-16383 , CVE-2026-39342 , CVE-2016-20096 , CVE-2023-28787 , CVE-2024-32128 , CVE-2025-1023 , CVE-2025-22785 , CVE-2025-32969 , CVE-2025-48281 , CVE-2025-54726 , CVE-2026-40329 , CVE-2026-40330 , CVE-2026-42647 , CVE-2026-54836 , CVE-2026-63106 , CVE-2026-65761 , CVE-2026-81672 , CVE-2026-81673 , CVE-2026-81674 , CVE-2026-81675 , CVE-2026-82526 , CVE-2026-9586 , CVE-2024-9465 , CVE-2021-37593 , CVE-2022-44727 , CVE-2024-5975 , CVE-2025-50455 , CVE-2026-15360 , CVE-2026-16532 , CVE-2026-73069 , CVE-2026-72851 , CVE-2016-20062 , CVE-2017-20243 , CVE-2017-20247 , CVE-2017-20249 , CVE-2017-20260 , CVE-2017-20261 , CVE-2017-20263 , CVE-2017-20266 , CVE-2017-20267 , CVE-2017-20268 , CVE-2017-20269 , CVE-2017-20271 , CVE-2017-20272 , CVE-2017-20273 , CVE-2017-20274 , CVE-2017-20275 , CVE-2017-20276 , CVE-2017-20277 , CVE-2017-20278 , CVE-2017-20279 , CVE-2017-20280 , CVE-2017-20281 , CVE-2017-20282 , CVE-2018-25340 , CVE-2018-25341 , CVE-2018-25342 , CVE-2018-25348 , CVE-2018-25351 , CVE-2018-25362 , CVE-2018-25364 , CVE-2018-25371 , CVE-2018-25372 , CVE-2018-25385 , CVE-2018-25386 , CVE-2018-25394 , CVE-2018-25395 , CVE-2018-25411 , CVE-2018-25413 , CVE-2018-25414 , CVE-2018-25416 , CVE-2018-25417 , CVE-2018-25418 , CVE-2018-25419 , CVE-2018-25420 , CVE-2018-25422 , CVE-2018-25424 , CVE-2018-25425 , CVE-2018-25428 , CVE-2018-25433 , CVE-2018-25434 , CVE-2019-25662 , CVE-2019-25668 , CVE-2019-25669 , CVE-2019-25675 , CVE-2019-25678 , CVE-2019-25680 , CVE-2019-25684 , CVE-2019-25694 , CVE-2019-25728 , CVE-2019-25730 , CVE-2019-25732 , CVE-2019-25745 , CVE-2019-25748 , CVE-2019-25750 , CVE-2019-25751 , CVE-2019-25752 , CVE-2019-25756 , CVE-2020-15876 , CVE-2020-15878 , CVE-2020-6010 , CVE-2021-47928 , CVE-2021-47930 , CVE-2022-0439 , CVE-2022-3142 , CVE-2022-3768 , CVE-2023-0630 , CVE-2023-7137 , CVE-2024-1751 , CVE-2024-35584 , CVE-2025-45868 , CVE-2026-31069 , CVE-2026-35395 , CVE-2026-35470 , CVE-2026-41075 , CVE-2026-44741 , CVE-2026-52775 , CVE-2026-55084 , CVE-2026-55509 , CVE-2026-70369 , CVE-2026-70370 , CVE-2026-70373 , CVE-2026-81676 , CVE-2026-81677 , CVE-2016-20097 , CVE-2019-25765 , CVE-2022-50997 , CVE-2024-58374 , CVE-2026-23921 , CVE-2026-27634 , CVE-2026-31844 , CVE-2026-34100 , CVE-2026-34101 , CVE-2026-34102 , CVE-2026-34103 , CVE-2026-34104 , CVE-2026-34105 , CVE-2026-35184 , CVE-2026-41453 , CVE-2026-44739 , CVE-2026-44886 , CVE-2026-50636 , CVE-2026-61518 , CVE-2026-72708 , CVE-2026-82527 , CVE-2026-82655 , CVE-2026-84208 , CVE-2026-85155 , CVE-2026-87807 , CVE-2024-13726 , CVE-2024-9186 , CVE-2026-11349 , CVE-2026-12721 , CVE-2026-16061 , CVE-2026-3326 , CVE-2026-3430 , CVE-2026-42425 , CVE-2026-73670 , CVE-2026-73850 , CVE-2026-76205 , CVE-2026-76635 , CVE-2026-79322 , CVE-2026-81728 , CVE-2026-44238 , CVE-2026-44706 , CVE-2026-65707 , CVE-2026-49489 , CVE-2026-64657 , CVE-2026-88890 , CVE-2026-52771 , CVE-2020-26248 , CVE-2026-14920 , CVE-2026-15258 , CVE-2026-39341 , CVE-2024-32136 , CVE-2014-9145 , CVE-2015-2196 , CVE-2020-22165 , CVE-2020-5766 , CVE-2021-24340 , CVE-2021-25899 , CVE-2021-27316 , CVE-2021-27319 , CVE-2021-27320 , CVE-2022-1453 , CVE-2022-1768 , CVE-2022-24265 , CVE-2022-24266 , CVE-2023-32590 , CVE-2023-36284 , CVE-2023-5203 , CVE-2023-5204 , CVE-2023-6063 , CVE-2023-6567 , CVE-2024-0705 , CVE-2024-11728 , CVE-2024-12025 , CVE-2024-13322 , CVE-2024-2879 , CVE-2024-8484 , CVE-2024-8522 , CVE-2024-8529 , CVE-2025-13138 , CVE-2025-2221 , CVE-2025-4396 , CVE-2025-5287 , CVE-2025-6970 , CVE-2026-10716 , CVE-2026-12987 , CVE-2026-1581 , CVE-2026-2413 , CVE-2026-2416 , CVE-2026-3018 , CVE-2026-3396 , CVE-2026-4060 , CVE-2026-51077 , CVE-2026-52476 , CVE-2026-52770 , CVE-2026-6854 , CVE-2026-78837 , CVE-2024-36683 , CVE-2025-67405 , CVE-2025-67406 , CVE-2025-67407 , CVE-2025-67408 , CVE-2025-69944 , CVE-2025-69945 , CVE-2025-69949 , CVE-2018-1002000 , CVE-2021-24554 , CVE-2021-24786 , CVE-2021-24791 , CVE-2021-24862 , CVE-2022-0228 , CVE-2022-31339 , CVE-2023-1211 , CVE-2024-0566 , CVE-2024-8625 , CVE-2026-27834 , CVE-2026-27885 , CVE-2026-39343 , CVE-2018-25346 , CVE-2018-25352 , CVE-2018-25392 , CVE-2018-25410 , CVE-2018-25429 , CVE-2018-25430 , CVE-2018-25431 , CVE-2019-25664 , CVE-2019-25749 , CVE-2019-25761 , CVE-2026-16007 , CVE-2026-18737 , CVE-2026-33714 , CVE-2026-48231 , CVE-2026-48232 , CVE-2026-48233 , CVE-2026-48234 , CVE-2026-48236 , CVE-2026-48237 , CVE-2026-48238 , CVE-2026-48239 , CVE-2026-48240 , CVE-2026-63080 , CVE-2026-72607 , CVE-2026-72609 , CVE-2026-75132 , CVE-2026-69704 , CVE-2024-10758 , CVE-2024-7188 , CVE-2026-14872 , CVE-2026-15153 , CVE-2015-4062 , CVE-2021-39165 , CVE-2023-27167 , CVE-2025-13652 , CVE-2026-14554 , CVE-2026-16065 , CVE-2026-34788 , CVE-2026-39229 , CVE-2026-72608 , CVE-2026-18403 , CVE-2026-16949 , CVE-2026-6428 , CVE-2025-6403 , CVE-2026-10178 , CVE-2026-10186 , CVE-2026-10249 , CVE-2026-10250 , CVE-2026-10251 , CVE-2026-10252 , CVE-2026-10253 , CVE-2026-10260 , CVE-2026-10261 , CVE-2026-10262 , CVE-2026-10263 , CVE-2026-10620 , CVE-2026-10704 , CVE-2026-11435 , CVE-2026-11456 , CVE-2026-11482 , CVE-2026-11483 , CVE-2026-11484 , CVE-2026-11485 , CVE-2026-11486 , CVE-2026-11488 , CVE-2026-11489 , CVE-2026-11490 , CVE-2026-11501 , CVE-2026-11582 , CVE-2026-16152 , CVE-2026-16154 , CVE-2026-16227 , CVE-2026-16228 , CVE-2026-16484 , CVE-2026-16765 , CVE-2026-19021 , CVE-2026-19196 , CVE-2026-19211 , CVE-2026-19343 , CVE-2026-19344 , CVE-2026-19384 , CVE-2026-19710 , CVE-2026-19899 , CVE-2026-19919 , CVE-2026-19926 , CVE-2026-45376 , CVE-2026-5368 , CVE-2026-5551 , CVE-2026-5554 , CVE-2026-5555 , CVE-2026-5564 , CVE-2026-5565 , CVE-2026-5575 , CVE-2026-5577 , CVE-2026-5634 , CVE-2026-5672 , CVE-2026-5805 , CVE-2026-5813 , CVE-2026-5814 , CVE-2026-5824 , CVE-2026-5829 , CVE-2026-7194 , CVE-2026-75014 , CVE-2026-75079 , CVE-2026-75080 , CVE-2026-75089 , CVE-2026-75778 , CVE-2026-75986 , CVE-2026-76048 , CVE-2026-76049 , CVE-2026-76574 , CVE-2026-76762 , CVE-2026-76764 , CVE-2026-76990 , CVE-2026-76996 , CVE-2026-76998 , CVE-2026-77019 , CVE-2026-77020 , CVE-2026-78143 , CVE-2026-78171 , CVE-2026-78197 , CVE-2026-78198 , CVE-2026-78199 , CVE-2026-78201 , CVE-2026-78244 , CVE-2026-78246 , CVE-2026-78247 , CVE-2026-78248 , CVE-2026-79804 , CVE-2026-79845 , CVE-2026-81203 , CVE-2026-82600 , CVE-2026-82610 , CVE-2026-82611 , CVE-2026-82612 , CVE-2026-82613 , CVE-2026-82614 , CVE-2026-82615 , CVE-2026-82701 , CVE-2026-84111 , CVE-2026-85187 , CVE-2026-85225 , CVE-2026-85379 , CVE-2026-85397 , CVE-2026-85398 , CVE-2026-85399 , CVE-2026-85402 , CVE-2026-85403 , CVE-2026-85516 , CVE-2026-86159 , CVE-2026-86160 , CVE-2026-86161 , CVE-2026-86162 , CVE-2026-86168 , CVE-2026-86180 , CVE-2026-86208 , CVE-2026-86209 , CVE-2026-86210 , CVE-2026-86211 , CVE-2026-86213 , CVE-2026-86220 , CVE-2026-86221 , CVE-2026-86222 , CVE-2026-86223 , CVE-2026-86224 , CVE-2026-86225 , CVE-2026-86268 , CVE-2026-86290 , CVE-2026-86298 , CVE-2026-9355 , CVE-2026-9356 , CVE-2026-9364 , CVE-2026-9383 , CVE-2026-9469 , CVE-2026-9470 , CVE-2026-9525 , CVE-2026-9526 , CVE-2026-9528 , CVE-2026-9573 , CVE-2026-9574 , CVE-2026-9575 , CVE-2026-9584 , CVE-2026-9606 , CVE-2023-6030 , CVE-2026-30520 , CVE-2026-38467 , CVE-2026-47720 , CVE-2026-5606 , CVE-2026-78864 , CVE-2026-85205 , CVE-2026-9524 , CVE-2026-38468 , CVE-2026-72610 , CVE-2026-14238 , CVE-2026-14189 , CVE-2026-15381 , CVE-2025-10592 , CVE-2025-13811 , CVE-2026-10170 , CVE-2026-10193 , CVE-2026-10202 , CVE-2026-10203 , CVE-2026-10204 , CVE-2026-10209 , CVE-2026-10256 , CVE-2026-10258 , CVE-2026-10265 , CVE-2026-10286 , CVE-2026-10296 , CVE-2026-10297 , CVE-2026-10302 , CVE-2026-10568 , CVE-2026-10808 , CVE-2026-10809 , CVE-2026-10811 , CVE-2026-10874 , CVE-2026-10875 , CVE-2026-11412 , CVE-2026-11475 , CVE-2026-11495 , CVE-2026-11506 , CVE-2026-11507 , CVE-2026-11508 , CVE-2026-11510 , CVE-2026-11513 , CVE-2026-11514 , CVE-2026-11529 , CVE-2026-11558 , CVE-2026-11559 , CVE-2026-11583 , CVE-2026-11584 , CVE-2026-11585 , CVE-2026-16131 , CVE-2026-16244 , CVE-2026-16334 , CVE-2026-16449 , CVE-2026-18766 , CVE-2026-18896 , CVE-2026-19020 , CVE-2026-19067 , CVE-2026-19068 , CVE-2026-19069 , CVE-2026-19070 , CVE-2026-19071 , CVE-2026-19347 , CVE-2026-19364 , CVE-2026-19767 , CVE-2026-19894 , CVE-2026-19917 , CVE-2026-19920 , CVE-2026-19921 , CVE-2026-19923 , CVE-2026-19934 , CVE-2026-19972 , CVE-2026-19973 , CVE-2026-20000 , CVE-2026-5206 , CVE-2026-5537 , CVE-2026-5543 , CVE-2026-5552 , CVE-2026-5553 , CVE-2026-5558 , CVE-2026-5560 , CVE-2026-5578 , CVE-2026-5579 , CVE-2026-5580 , CVE-2026-5583 , CVE-2026-5620 , CVE-2026-5635 , CVE-2026-5636 , CVE-2026-5675 , CVE-2026-5681 , CVE-2026-5719 , CVE-2026-5823 , CVE-2026-7196 , CVE-2026-75086 , CVE-2026-75087 , CVE-2026-75088 , CVE-2026-75876 , CVE-2026-76785 , CVE-2026-76991 , CVE-2026-76997 , CVE-2026-77025 , CVE-2026-78056 , CVE-2026-78057 , CVE-2026-78112 , CVE-2026-78185 , CVE-2026-78200 , CVE-2026-78656 , CVE-2026-8231 , CVE-2026-82421 , CVE-2026-82422 , CVE-2026-82424 , CVE-2026-82484 , CVE-2026-82485 , CVE-2026-82540 , CVE-2026-82541 , CVE-2026-82545 , CVE-2026-82609 , CVE-2026-82696 , CVE-2026-84109 , CVE-2026-84153 , CVE-2026-85383 , CVE-2026-86163 , CVE-2026-86164 , CVE-2026-86170 , CVE-2026-86171 , CVE-2026-86172 , CVE-2026-86232 , CVE-2026-86233 , CVE-2026-86234 , CVE-2026-86235 , CVE-2026-86236 , CVE-2026-86245 , CVE-2026-86265 , CVE-2026-86267 , CVE-2026-86269 , CVE-2026-86270 , CVE-2026-86291 , CVE-2026-86309 , CVE-2026-86310 , CVE-2026-86517 , CVE-2026-86518 , CVE-2026-86675 , CVE-2026-9342 , CVE-2026-9450 , CVE-2026-9451 , CVE-2026-9542 , CVE-2026-9607 , CVE-2026-10155 , CVE-2026-10171 , CVE-2026-19787 , CVE-2026-19925 , CVE-2026-85643 , CVE-2026-86667
CWE-94CVE-2026-44262 , CVE-2026-76635
CWE-200CVE-2014-9147
CWE-266CVE-2026-11476
CWE-284CVE-2014-9148
CWE-285CVE-2026-11476
CWE-287CVE-2026-48528 , CVE-2021-39165
CWE-306CVE-2019-25678
CWE-352CVE-2022-0439
CWE-434CVE-2026-39931
CWE-862CVE-2025-70150 , CVE-2026-85512
CWE-863CVE-2026-85512
CWE-918CVE-2026-26379

Documentation Source

  • Original wiki page: WAF 380122
  • Source revision: 6048
  • Source revision date: 2020-08-24