Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

type:sqli — CVE vulnerabilities tagged 22141

22141 CVE security advisories tagged "type:sqli" with AI Chinese analysis, CVSS, references and POCs.

The tag "type:sqli" identifies vulnerabilities classified as SQL Injection, a critical web security flaw where attackers interfere with the queries an application makes to its database. This occurs when untrusted data is concatenated into SQL commands without proper sanitization or parameterization, allowing malicious users to execute arbitrary database operations. Such injections can lead to severe consequences, including unauthorized data access, modification, or deletion, and potentially full system compromise. Typical scenarios involve vulnerable login forms, search fields, or URL parameters where user input is directly embedded into backend queries. With over 20,000 associated CVEs, this persistent threat underscores the necessity of implementing robust input validation, prepared statements, and strict database access controls to mitigate risks and protect sensitive information from exploitation.

CVE ID Title CVSS Severity Published
CVE-2026-85643 code-projects Online Shopping System adduser.php mysqli_query sql injection — Online Shopping System CWE-89 4.7 Medium 2026-09-04
CVE-2026-53756 Emlog Blind SQL Injection via Authentication Cookie — emlog CWE-89 4.9 Medium 2026-09-04
CVE-2026-82538 ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter — ILIAS CWE-89 8.8 High 2026-09-04
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed — Operational Decision Manager CWE-89 9.8 Critical 2026-09-04
CVE-2026-85689 llmware 0.4.6 SQL Injection via unescaped filter values — llmware CWE-89 6.5 Medium 2026-09-04
CVE-2026-52691 Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module — Apache Griffin Hive Metastore Module CWE-89 - - 2026-09-04
CVE-2026-85516 code-projects Vehicle Management System busprofile.php sql injection — Vehicle Management System CWE-89 7.3 High 2026-09-04
CVE-2026-18198 SQL Injection in TAC Information's GoldenHorn — GOLDENHORN ONEIT CWE-89 8.8 High 2026-09-04
CVE-2026-19051 Plaintext Storage of User Credentials in Menulux Software's Menulux Portal — Menulux Portal CWE-256 7.1 High 2026-09-04
CVE-2026-85540 Interinfo|DreamMaker - SQL Injection — DreamMaker CWE-89 8.8 High 2026-09-04
CVE-2026-57777 WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability — WooCommerce CWE-89 7.6 High 2026-09-04
CVE-2026-82186 WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter — WPLP Cookie Consent - - 2026-09-04
CVE-2026-85403 code-projects Doctor Appointment System contactus.php sql injection — Doctor Appointment System CWE-89 7.3 High 2026-09-04
CVE-2026-85402 code-projects Doctor Appointment System booking.php sql injection — Doctor Appointment System CWE-89 7.3 High 2026-09-04
CVE-2026-85399 code-projects Hospital Information System PrespController.php getSinglePresp sql injection — Hospital Information System CWE-89 7.3 High 2026-09-04
CVE-2026-85398 code-projects Hospital Information System viewReq.php viewReq sql injection — Hospital Information System CWE-89 7.3 High 2026-09-04
CVE-2026-85397 code-projects Hospital Information System addReq.php findBySearch sql injection — Hospital Information System CWE-89 7.3 High 2026-09-04
CVE-2026-85383 itsourcecode Sales and Inventory System inv_del.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-09-04
CVE-2026-85379 light0011 cms Query Builder ChapterController.class.php searchChapter sql injection — cms CWE-89 7.3 High 2026-09-04
CVE-2025-67066 oasys sysoa 1.0 /outaddresspaging SQL注入 — n/a - - 2026-09-04
CVE-2026-71622 Zhao-github APiAdmin 5.0.1 User.php 组件 SQL注入漏洞 — n/a - - 2026-09-04
CVE-2026-85225 code-projects Doctor Appointment System patient_login.php sql injection — Doctor Appointment System CWE-89 7.3 High 2026-09-03
CVE-2026-82527 R2R 3.6.6 SQL Injection via Retrieval Search Filter Key — R2R CWE-89 7.5 High 2026-09-03
CVE-2026-85205 itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injection — Online Medicine Delivery System CWE-89 6.3 Medium 2026-09-03
CVE-2026-85388 Worklenz through 3.0.0 SQL Injection via the sort-field Query Parameter — worklenz CWE-89 8.1 High 2026-09-03
CVE-2026-82526 R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint — R2R CWE-89 9.8 Critical 2026-09-03
CVE-2026-85187 itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injection — Online Medicine Delivery System CWE-89 7.3 High 2026-09-03
CVE-2026-84813 WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability — GeoDirectory CWE-89 9.3 Critical 2026-09-03
CVE-2026-84768 WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability — VikAppointments Services Booking Calendar CWE-89 9.3 Critical 2026-09-03
CVE-2026-85138 SeaCMS WeChat index.php addslashes sql injection — SeaCMS CWE-89 7.3 High 2026-09-03

Vulnerabilities classified as type:sqli represent 22141 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.