SQL Injection Vulnerabilities

80 advisories classified as SQL Injection

80

Total CVEs

19

Critical

61

High

CVE-2026-37749

Apr 17, 2026

Critical (9.8)

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php....

Read Advisory

CVE-2026-40351

Apr 17, 2026

Critical (9.8)

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attack...

Read Advisory

CVE-2026-40352

Apr 17, 2026

High (8.8)

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verifica...

Read Advisory

CVE-2025-63939

Apr 14, 2026

Critical (9.8)

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter....

Read Advisory

CVE-2025-65135

Apr 14, 2026

Critical (9.8)

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter....

Read Advisory

CVE-2026-6142

Apr 13, 2026

High (7.3)

A vulnerability was identified in tushar-2223 Hotel Management System up to bb1f3b3666124b888f1e4bcf51b6fba9fbb01d15. Affected by this vulnerability is an unknown functionality of the file /admin/room...

Read Advisory

CVE-2026-6148

Apr 13, 2026

High (7.3)

A vulnerability was detected in code-projects Vehicle Showroom Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /util/MonthTotalReportUpdateFunction.php. P...

Read Advisory

CVE-2026-6149

Apr 13, 2026

High (7.3)

A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Affected by this issue is some unknown functionality of the file /util/BookVehicleFunction.php. Executing a manipulation ...

Read Advisory

CVE-2026-6151

Apr 13, 2026

High (7.3)

A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unknown code of the file /util/PaymentStatusFunction.php. The manipulation of the argument...

Read Advisory

CVE-2026-6152

Apr 13, 2026

High (7.3)

A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This issue affects some unknown processing of the file /util/StaffAddingFunction.php. This manipulation of the a...

Read Advisory

CVE-2026-6153

Apr 13, 2026

High (7.3)

A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the file /util/StaffDetailsFunction.php. Such manipulation of the argument ST...

Read Advisory

CVE-2019-25697

Apr 12, 2026

High (8.2)

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requ...

Read Advisory

CVE-2019-25710

Apr 12, 2026

High (8.2)

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malici...

Read Advisory

CVE-2019-25668

Apr 5, 2026

High (8.2)

News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers ca...

Read Advisory

CVE-2019-25674

Apr 5, 2026

High (8.2)

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requ...

Read Advisory

CVE-2019-25675

Apr 5, 2026

High (8.2)

eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameter...

Read Advisory

CVE-2019-25676

Apr 5, 2026

High (8.2)

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inje...

Read Advisory

CVE-2019-25678

Apr 5, 2026

High (8.2)

C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through t...

Read Advisory

CVE-2019-25684

Apr 5, 2026

High (8.2)

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GE...

Read Advisory

CVE-2026-5540

Apr 5, 2026

High (7.3)

A vulnerability has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modifymember.php of the component Parameter Handler. Such manipulation o...

Read Advisory

CVE-2025-13855

Apr 1, 2026

High (7.6)

IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, ...

Read Advisory

CVE-2026-32714

Mar 31, 2026

Critical (9.8)

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to co...

Read Advisory

CVE-2026-5019

Mar 29, 2026

High (7.3)

A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Paramet...

Read Advisory

CVE-2026-5034

Mar 29, 2026

High (7.3)

A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation ...

Read Advisory

CVE-2026-5033

Mar 29, 2026

High (7.3)

A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The m...

Read Advisory

CVE-2026-5017

Mar 28, 2026

High (7.3)

A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipu...

Read Advisory

CVE-2026-5018

Mar 28, 2026

High (7.3)

A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulati...

Read Advisory

CVE-2018-25195

Mar 26, 2026

High (8.2)

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submi...

Read Advisory

CVE-2018-25203

Mar 26, 2026

High (8.2)

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers ca...

Read Advisory

CVE-2026-4540

Mar 22, 2026

High (7.3)

A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parameters Handler. The manipulation o...

Read Advisory

CVE-2019-25573

Mar 21, 2026

High (7.1)

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cat parameter. Attackers can send GET...

Read Advisory

CVE-2019-25575

Mar 21, 2026

High (8.2)

SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'p' and 's' parameters. Att...

Read Advisory

CVE-2019-25576

Mar 21, 2026

High (8.2)

Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Atta...

Read Advisory

CVE-2019-25578

Mar 21, 2026

High (8.2)

phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the idnews parameter. Attackers can send...

Read Advisory

CVE-2019-25580

Mar 21, 2026

High (8.2)

ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET ...

Read Advisory

CVE-2019-25581

Mar 21, 2026

High (8.2)

i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers ...

Read Advisory

CVE-2026-33134

Mar 20, 2026

Critical (9.3)

WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability a...

Read Advisory

CVE-2026-22730

Mar 18, 2026

High (8.8)

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability ...

Read Advisory

CVE-2015-20121

Mar 16, 2026

High (8.2)

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitrary SQL code through the GET parame...

Read Advisory

CVE-2026-32628

Mar 16, 2026

High (8.8)

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Age...

Read Advisory

CVE-2019-25482

Mar 12, 2026

High (8.2)

Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the arac_kateg...

Read Advisory

CVE-2019-25488

Mar 12, 2026

High (8.2)

Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipulate database queries through GET parameters. Attac...

Read Advisory

CVE-2019-25508

Mar 12, 2026

High (8.2)

Jettweb Php Hazir Ilan Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'kat' parameter....

Read Advisory

CVE-2019-25509

Mar 12, 2026

High (8.2)

XooDigital Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET r...

Read Advisory

CVE-2019-25511

Mar 12, 2026

High (8.2)

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the videoid paramet...

Read Advisory

CVE-2019-25512

Mar 12, 2026

High (8.2)

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST requests. Attackers can ma...

Read Advisory

CVE-2019-25513

Mar 12, 2026

High (8.2)

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter. ...

Read Advisory

CVE-2019-25514

Mar 12, 2026

High (8.2)

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the kelime parameter in POST requests. Attackers can ma...

Read Advisory

CVE-2026-31896

Mar 11, 2026

Critical (9.8)

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract(...

Read Advisory

CVE-2026-3843

Mar 10, 2026

Critical (9.8)

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially craf...

Read Advisory

CVE-2018-25161

Mar 6, 2026

High (8.2)

Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting malicious code through the txtCustomerCode, txtCustomerName...

Read Advisory

CVE-2018-25163

Mar 6, 2026

High (8.2)

BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in for...

Read Advisory

CVE-2018-25166

Mar 6, 2026

High (8.2)

Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attac...

Read Advisory

CVE-2018-25167

Mar 6, 2026

High (8.2)

Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit malicio...

Read Advisory

CVE-2018-25172

Mar 6, 2026

High (8.2)

Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET...

Read Advisory

CVE-2018-25170

Mar 6, 2026

High (8.2)

DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id, idC, and idU parameters. Attackers can ...

Read Advisory

CVE-2018-25173

Mar 6, 2026

High (8.2)

Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the gid parameter. Attackers can send GET req...

Read Advisory

CVE-2019-25499

Mar 4, 2026

High (8.2)

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send PO...

Read Advisory

CVE-2019-25501

Mar 4, 2026

High (8.2)

Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the app_id parameter. Attackers can send POST req...

Read Advisory

CVE-2026-26710

Mar 2, 2026

Critical (9.8)

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php....

Read Advisory

CVE-2026-26711

Mar 2, 2026

Critical (9.8)

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php....

Read Advisory

CVE-2026-26712

Mar 2, 2026

Critical (9.8)

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php....

Read Advisory

CVE-2026-26713

Mar 2, 2026

Critical (9.8)

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php....

Read Advisory

CVE-2025-13673

Feb 28, 2026

High (7.5)

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient...

Read Advisory

CVE-2026-28562

Feb 28, 2026

High (8.2)

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql() sanitization on unquoted identifiers. Attackers ...

Read Advisory

CVE-2025-11252

Feb 27, 2026

Critical (9.8)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects w...

Read Advisory

CVE-2026-24494

Feb 23, 2026

Critical (9.8)

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a ...

Read Advisory

CVE-2019-25366

Feb 22, 2026

High (8.2)

microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Attacke...

Read Advisory

CVE-2019-25391

Feb 22, 2026

High (8.2)

Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter. Attackers can send POST...

Read Advisory

CVE-2019-25433

Feb 22, 2026

High (8.2)

XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET req...

Read Advisory

CVE-2019-25439

Feb 22, 2026

High (8.2)

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can cra...

Read Advisory

CVE-2025-10970

Feb 20, 2026

Critical (9.8)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection.This issue affects Talentics: through 200...

Read Advisory

CVE-2025-70149

Feb 18, 2026

Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter....

Read Advisory

CVE-2025-70152

Feb 18, 2026

Critical (9.8)

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack...

Read Advisory

CVE-2024-55270

Feb 17, 2026

High (8.8)

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter....

Read Advisory

CVE-2025-70397

Feb 17, 2026

High (8.8)

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter....

Read Advisory

CVE-2025-7631

Feb 17, 2026

High (8.6)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Information Advertising and Consulting Services Trade Ltd. C...

Read Advisory

CVE-2026-2024

Feb 14, 2026

High (7.5)

The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied para...

Read Advisory

CVE-2025-69633

Feb 13, 2026

Critical (9.8)

A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execut...

Read Advisory

CVE-2025-70981

Feb 12, 2026

Critical (9.8)

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter....

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.