Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Drizzle HIGH 7.5
CVE-2026-39356

Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific …

Fix: 0.45.2+
Fix from $1,950 2026-04-07
Unclassified HIGH 7.3
CVE-2026-5736

A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src…

Patch available
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.1
CVE-2026-39340

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the adm…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.1
CVE-2026-39341

ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper in…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39342

ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 7.2
CVE-2026-39343

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEventTypes.php file, which is o…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39334

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.ph…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39329

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM. …

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39330

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 7.2
CVE-2026-39325

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsUser.php in C…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39326

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.ph…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39327

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php …

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39318

ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRo…

Fix: after 7.0.5
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39319

ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaise…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Frappe CRITICAL 9.8
CVE-2026-35614

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fix…

Fix: 15.104.0 / 16.14.0+
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.9
CVE-2026-23696EPSS 16%

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allo…

Patch available
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.8
CVE-2024-36058

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parame…

Mitigation only
Fix from $2,300 2026-04-07
Runzero Platform MEDIUM 6.4
CVE-2026-5372

An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Imp…

Mitigation only
Fix from $1,600 2026-04-07
Sql Chart Builder MEDIUM 6.5
CVE-2026-4079

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for at…

Fix: 2.3.8+
Fix from $1,600 2026-04-07
Unclassified MEDIUM 6.3
CVE-2026-5719

A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a…

Mitigation only
Fix from $1,600 2026-04-07
Wegia HIGH 8.8
CVE-2026-35395

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection …

Fix: 3.6.9+
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5681

A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the com…

Mitigation only
Fix from $1,600 2026-04-06
Ecclesiacrm CRITICAL 9.8
CVE-2026-35184

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the…

Fix: 8.0.0+
Fix from $2,300 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5672

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edi…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5675

A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the comp…

Mitigation only
Fix from $1,600 2026-04-06
Openstamanager HIGH 8.8
CVE-2026-35470

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across differ…

Fix: 2.10.2+
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5669

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unkn…

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 7.3
CVE-2026-5665

A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the …

Mitigation only
Fix from $1,950 2026-04-06
Unclassified HIGH 8.5
CVE-2026-34885

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQ…

Mitigation only
Fix from $1,950 2026-04-06
Glpi CRITICAL 9.8
CVE-2026-26263EPSS 9%

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…

Fix: 11.0.6+
Fix from $2,300 2026-04-06