Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-89'

View all threats tagged with 'cwe-89'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-89

Threats Tagged 'cwe-89'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-19211: SQL Injection in SourceCodester Photo Share WebsiteCVE-2026-19211
0

SourceCodester Photo Share Website 1.0 contains a SQL injection vulnerability in the /social/ajax.php?action=signup endpoint. The vulnerability arises from manipulation of the email argument, allowing remote attackers to execute SQL injection attacks. Exploit code has been publicly disclosed, but no official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-64636: Vulnerability in WebPros PleskCVE-2026-64636
0

An SQL injection vulnerability exists in Plesk Obsidian up to version 18.0.80 for Linux and Windows. This flaw allows an authenticated user to read arbitrary data from the panel database without requiring user interaction. The vulnerability has a high severity rating with a CVSS score of 7.7.

Join the discussion
CVE-2026-16589: CWE-89 SQL Injection in WP Directory KitCVE-2026-16589
0

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.

Join the discussion
CVE-2026-19196: SQL Injection in SourceCodester Photo Share WebsiteCVE-2026-19196
0

A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

Join the discussion
CVE-2026-66838: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in elixir-ecto postgrexCVE-2026-66838
0

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and extend the streamed statement with their own clauses, which execute under the connection's role. Ecto exposes the same option through Ecto.Repo.stream/2. Postgrex appends the comment by concatenating it into the statement text sent in the Parse message, without escaping or rejecting */. The option is validated by comment_not_present!/1 at every other execution point; stream/4 never calls it. Because Parse accepts a single command, the injection is confined to the streamed statement and further statements cannot be chained. This issue affects postgrex: from 0.19.3 before 0.22.4.

Join the discussion
CVE-2026-15361: CWE-89 SQL Injection in Content ViewsCVE-2026-15361
0

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.

Join the discussion
CVE-2026-19062: SQL Injection in chiuwingyan houseCVE-2026-19062
0

A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument zuname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion
CVE-2026-19069: SQL Injection in itsourcecode Hospital Management SystemCVE-2026-19069
0

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /treatmentrecord.php. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

Join the discussion
CVE-2026-19070: SQL Injection in itsourcecode Hospital Management SystemCVE-2026-19070
0

A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewadmin.php. The manipulation of the argument delid results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Join the discussion
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the field and order parameters in paginated… (CVE-2026-67689)CVE-2026-67689
0

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

Join the discussion

Showing 1 to 10 of 224 results

Filters:Tag: cwe-89
Page 1 of 23
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses