Threats Tagged 'cwe-89'
View all threats tagged with 'cwe-89'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-89'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-61685 is a SQL Injection vulnerability in ReactPress prior to version 3.7.0. The issue arises because the API list endpoints use unsanitized HTTP query parameter names as SQL column identifiers in TypeORM QueryBuilder conditions. Since TypeORM parameterizes values but not column names, attackers can inject SQL through crafted query string keys. This vulnerability allows unauthenticated attackers to execute unauthorized SQL commands. Version 3.7.0 includes a patch that fixes this issue. A recommended workaround is to allowlist permitted filter column names before using them in SQL queries. Join the discussion | CVE Database V5 | 09/22/2026, 23:08:58 UTC Added: 09/22/2026, 23:18:19 UTC |
IBM Financial Transaction Manager (FTM) for RedHat OpenShift version 4.0.6.0 contains a high-severity SQL injection vulnerability (CWE-89) that allows remote attackers to execute arbitrary ESQL commands due to improper neutralization of special elements in an ESQL command. Join the discussion | CVE Database V5 | 09/22/2026, 22:02:44 UTC Added: 09/22/2026, 22:18:14 UTC |
0 CVE-2026-75682 is a critical SQL Injection vulnerability in Adobe Connect that allows a low-privileged attacker to execute arbitrary SQL commands without user interaction. This flaw could lead to arbitrary code execution in the context of the current user, potentially resulting in elevated access or control over victim accounts or sessions. The vulnerability affects Adobe Connect versions up to and including 12.11 and 4.4. The vulnerability has a high CVSS score of 9.9, indicating severe impact on confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 09/22/2026, 18:54:01 UTC Added: 09/22/2026, 19:03:31 UTC |
Adobe Campaign Classic contains a critical SQL Injection vulnerability (CVE-2026-82009) that allows an attacker with high privileges to execute arbitrary SQL commands without user interaction. This vulnerability can lead to arbitrary code execution within the context of the current user and affects the scope of the application. Join the discussion | CVE Database V5 | 09/22/2026, 17:40:00 UTC Added: 09/22/2026, 17:48:22 UTC |
Adobe Campaign Classic contains a critical SQL Injection vulnerability (CVE-2026-82011) that allows a low-privileged attacker to bypass security features and gain unauthorized read and limited write access without user interaction. The vulnerability involves improper neutralization of special elements in SQL commands, changing the security scope. It has a high CVSS score of 9.1, indicating severe impact. No patch or remediation details are currently provided. Join the discussion | CVE Database V5 | 09/22/2026, 17:39:53 UTC Added: 09/22/2026, 17:48:24 UTC |
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. Join the discussion | CVE Database V5 | 09/22/2026, 17:39:50 UTC Added: 09/22/2026, 17:48:24 UTC |
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. Join the discussion | CVE Database V5 | 09/22/2026, 14:10:27 UTC Added: 09/22/2026, 14:33:35 UTC |
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The vendor was contacted and it was learned that the product is not supported. Join the discussion | CVE Database V5 | 09/22/2026, 13:51:45 UTC Added: 09/22/2026, 14:03:19 UTC |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3. Join the discussion | CVE Database V5 | 09/22/2026, 09:13:36 UTC Added: 09/22/2026, 09:33:18 UTC |
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content. Join the discussion | CVE Database V5 | 09/20/2026, 17:53:02 UTC Added: 09/20/2026, 18:02:12 UTC |
Showing 1 to 10 of 2203 results