Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-89 (SQL命令中使用的特殊元素转义处理不恰当(SQL注入)) — Vulnerability Class 8827

8827 vulnerabilities classified as CWE-89 (SQL命令中使用的特殊元素转义处理不恰当(SQL注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-5648 code-projects Simple Laundry System Parameter userfinishregister.php sql injection — Simple Laundry System 7.3 High2026-04-06
CVE-2026-5646 code-projects Easy Blog Site login.php sql injection — Easy Blog Site 7.3 High2026-04-06
CVE-2026-5645 projectworlds Car Rental System Parameter pay.php sql injection — Car Rental System 7.3 High2026-04-06
CVE-2026-5641 PHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injection — Online Shopping Portal Project 6.3 Medium2026-04-06
CVE-2026-5640 PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection — Online Shopping Portal Project 6.3 Medium2026-04-06
CVE-2026-5639 PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection — Online Shopping Portal Project 6.3 Medium2026-04-06
CVE-2026-5637 projectworlds Car Rental System Parameter message_admin.php sql injection — Car Rental System 7.3 High2026-04-06
CVE-2026-5636 PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection — Online Shopping Portal Project 6.3 Medium2026-04-06
CVE-2026-5635 PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection — Online Shopping Portal Project 6.3 Medium2026-04-06
CVE-2026-5634 projectworlds Car Rental Project Parameter book_car.php sql injection — Car Rental Project 7.3 High2026-04-06
CVE-2026-5620 itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection — Construction Management System 6.3 Medium2026-04-06
CVE-2026-5606 PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection — Online Shopping Portal Project 6.3 Medium2026-04-06
CVE-2019-25675 eDirectory All Versions SQL Injection Authentication Bypass — eDirectory 8.2 High2026-04-05
CVE-2019-25704 Kados R10 GreenBee SQL Injection via filter_user_mail — Kados R10 GreenBee 8.2 High2026-04-05
CVE-2019-25702 Kados R10 GreenBee SQL Injection via id_project Parameter — Kados R10 GreenBee 8.2 High2026-04-05
CVE-2019-25700 Kados R10 GreenBee SQL Injection via sort_direction Parameter — Kados R10 GreenBee 8.2 High2026-04-05
CVE-2019-25698 Kados R10 GreenBee SQL Injection via id_to_delete Parameter — Kados R10 GreenBee 8.2 High2026-04-05
CVE-2019-25696 Kados R10 GreenBee SQL Injection via language_tag Parameter — Kados R10 GreenBee 8.2 High2026-04-05
CVE-2019-25694 Kados R10 GreenBee SQL Injection via user2reset — Kados R10 GreenBee 8.2 High2026-04-05
CVE-2019-25692 Kados R10 GreenBee SQL Injection via id_to_modify Parameter — Kados R10 GreenBee 8.2 High2026-04-05
CVE-2019-25690 Kados R10 GreenBee SQL Injection via mng_profile_id — Kados R10 GreenBee 8.2 High2026-04-05
CVE-2019-25688 Kados R10 GreenBee SQL Injection via menu_lev1 Parameter — Kados GreenBee 8.2 High2026-04-05
CVE-2019-25684 OpenDocMan 1.3.4 SQL Injection via where Parameter — OpenDocMan 8.2 High2026-04-05
CVE-2019-25680 Advance Gift Shop Pro Script 2.0.3 SQL Injection via search — Advance Gift Shop Pro Script 8.2 High2026-04-05
CVE-2019-25674 CMSsite 1.0 SQL Injection via post Parameter — CMSsite 8.2 High2026-04-05
CVE-2019-25672 PilusCart 1.4.1 SQL Injection via send Parameter — PilusCart 8.2 High2026-04-05
CVE-2019-25669 qdPM 9.1 SQL Injection via search_by_extrafields Parameter — qdPM 8.2 High2026-04-05
CVE-2019-25668 News Website Script 2.0.5 SQL Injection via index.php — News Website Script 8.2 High2026-04-05
CVE-2019-25664 SuiteCRM 7.10.7 SQL Injection via record Parameter — SuiteCRM 7.1 High2026-04-05
CVE-2019-25663 SuiteCRM 7.10.7 SQL Injection via parentTab Parameter — SuiteCRM 7.1 High2026-04-05

Vulnerabilities classified as CWE-89 (SQL命令中使用的特殊元素转义处理不恰当(SQL注入)) represent 8827 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.