Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Online Art Gallery Shop CRITICAL 9.8
CVE-2026-3406

A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.p…

Mitigation only
Fix from $2,300 2026-03-02
Wpforo Forum CRITICAL 9.8
CVE-2026-28562

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql…

Fix: 2.4.15+
Fix from $2,300 2026-02-28
Unclassified HIGH 7.5
CVE-2025-13673

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versi…

Mitigation only
Fix from $1,950 2026-02-28
Opendcim HIGH 8.8
CVE-2026-28516

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-ins…

Patch available
Fix from $1,950 2026-02-27
Group Office HIGH 8.8
CVE-2026-27832

Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, and 6.8.153 have a SQL Injectio…

Fix: 6.8.153 / 25.0.87+
Fix from $1,950 2026-02-27
Airbnb Clone Script HIGH 8.2
CVE-2019-25494

Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication…

No fix yet
Fix from $1,950 2026-02-27
Oscommerce HIGH 7.5
CVE-2019-25495

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

No fix yet
Fix from $1,950 2026-02-27
Oscommerce HIGH 7.5
CVE-2019-25496

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

No fix yet
Fix from $1,950 2026-02-27
Oscommerce HIGH 7.5
CVE-2019-25497

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

Fix: after 2.3.4.1
Fix from $1,950 2026-02-27
Airbnb Clone Script HIGH 7.5
CVE-2019-25490

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug…

No fix yet
Fix from $1,950 2026-02-27
Airbnb Clone Script HIGH 7.5
CVE-2019-25491

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu…

No fix yet
Fix from $1,950 2026-02-27
Airbnb Clone Script HIGH 7.5
CVE-2019-25492

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu…

No fix yet
Fix from $1,950 2026-02-27
Airbnb Clone Script HIGH 7.5
CVE-2019-25493

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu…

No fix yet
Fix from $1,950 2026-02-27
Airbnb Clone Script CRITICAL 9.1
CVE-2019-25489

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug…

No fix yet
Fix from $2,300 2026-02-27
Centreon Web CRITICAL 9.8
CVE-2026-2751

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (S…

Fix: 24.04.24. / 24.10.20+
Fix from $2,300 2026-02-27
Unclassified CRITICAL 9.3
CVE-2025-15498

Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to b…

Mitigation only
Fix from $2,300 2026-02-27
Windesk.fm CRITICAL 9.8
CVE-2025-11252

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. W…

Fix: after 27022026
Fix from $2,300 2026-02-27
Woyio CRITICAL 9.8
CVE-2025-11251

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Comm…

Mitigation only
Fix from $2,300 2026-02-27
Youlai Mall CRITICAL 9.8
CVE-2026-3287

A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/m…

Mitigation only
Fix from $2,300 2026-02-27
Jizhicms HIGH 8.8
CVE-2026-3292

A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the compon…

Fix: after 2.5.6
Fix from $1,950 2026-02-27
Phishing Club MEDIUM 6.5
CVE-2026-28226

Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL injection vulnerability exists …

Fix: 1.30.2+
Fix from $1,600 2026-02-26
School Management System CRITICAL 9.8
CVE-2026-3261

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component…

Mitigation only
Fix from $2,300 2026-02-26
Discourse MEDIUM 6.5
CVE-2026-27149

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in PM tag filtering (`list_privat…

Fix: 2025.12.2 / 2026.1.1+
Fix from $1,600 2026-02-26
Spip HIGH 8.8
CVE-2026-22206

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by…

Fix: 4.4.10+
Fix from $1,950 2026-02-26
Unclassified HIGH 8.6
CVE-2026-1198

SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated…

Mitigation only
Fix from $1,950 2026-02-26
Unclassified HIGH 7.6
CVE-2026-28136

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection.T…

Mitigation only
Fix from $1,950 2026-02-26
Fleet HIGH 8.8
CVE-2026-26186

Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authenticated users to inject arbi…

Fix: 4.80.1+
Fix from $1,950 2026-02-26
N8n HIGH 8.8
CVE-2026-27497

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $1,950 2026-02-25
Unclassified HIGH 7.3
CVE-2026-3200

A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/getUser/getUsers of the file /s…

Mitigation only
Fix from $1,950 2026-02-25
Openemr HIGH 8.8
CVE-2026-25746

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL inject…

Fix: 8.0.0+
Fix from $1,950 2026-02-25