Web Vulnerability Scanners
Web vulnerability scanners test HTTP/HTTPS endpoints for injection flaws, broken authentication, sensitive data exposure, and logic errors. Use these tools to continuously monitor your public-facing applications before attackers do.
Important Web Vulnerabilities Scanners
Online Generic SQL Injection Vulnerability Scanner
Detect SQL Injection vulnerabilities in your web applications
Free and Online Generic XSS Scanner
XSS Vulnerability is a type of vulnerability typically found in web applications. It occurs when user input data is not correctly filtered or sanitized before being returned to the end-user.
Generic SSRF Vulnerability Scanner
Server-side request forgery (SSRF), is a vulnerability that allows an attacker to execute unauthorized requests from the perspective of the webserver. SSRF can be used to access sensitive data, such as internal network resources and user data, or to launch attacks on other systems from the webserver.The impact of SSRF attacks can be significant. They can allow attackers to arbitrary command execution, access internal apps, and even scan ports in the local network.
Generic Server Side Template Injection (SSTI) Vulnerability Scanner
Detects 'Server Side Template Injection (SSTI)' vulnerability in Web Application. Identifies injectable template contexts that allow server-side evaluation of attacker-controlled expressions, enabling data exposure or remote code execution if exploited.
Online Generic File Inclusion - LFI/RFI Vulnerability Scanner
File inclusion vulnerabilities are a type of vulnerability that occurs when an attacker is able to include a file, usually through using inputs on the webserver. These vulnerabilities can lead to information disclosure, arbitrary code execution, and full system compromise.
Generic Blind XXE Scanner
Generic Blind XXE Scanner
Generic Command Injection Vulnerability Scanner
A command injection vulnerability occurs when an attacker is able to pass malicious input to a program and have that input executed as an OS command. This can allow attackers to run operation system-level command execution. Command injection is often possible due to insecure coding practices that do not properly validate or sanitize user input.
HTTP Header Command Injection Vulnerability Fuzz & Scanner
You can fuzz HTTP headers for command injection using this tool.
Cache Poisoning to Stored XSS Vulnerability Scanner
This scanner identifies vulnerabilities where cache poisoning could lead to stored XSS, enabling attackers to inject malicious scripts that are executed when the cached content is served.
### Arachni ### Web Application Source Code Disclosure Scanner
Detects 'Source Code Disclosure' vulnerability in Web Application affecting exposed source/config files and repository artifacts. This scanner finds accessible source files, backups, and repository metadata that may reveal sensitive code and secrets.
### Arachni ### Generic Code Injection Vulnerability Scanner
Detects 'Code Injection' vulnerability. This scanner identifies weaknesses in web applications, built with technologies like PHP, Ruby, Python, Java, and ASP, where an attacker can introduce and execute arbitrary code. Detecting this critical flaw prevents unauthorized server access and potential system compromise.
Halo ITSM SQL Injection Scanner
Detects 'SQL Injection' vulnerability in Halo ITSM.
Windows LFI Vulnerability Scanner
Detect and Protect Against Windows LFI Vulnerabilities
Generic Linux LFI Detection Scanner
Identify and Mitigate Local File Inclusion Vulnerabilities in Linux Systems
J2EE LFI Vulnerability Scanner
Detect potential Local File Inclusion (LFI) vulnerabilities within J2EE applications, focusing on unauthorized access to critical files such as web.xml, which could lead to sensitive information disclosure.
CPAS Management System SQL Injection Scanner
Detects 'SQL Injection' vulnerability in CPAS Management System affects v. 4. This scanner identifies critical flaws allowing unauthorized data retrieval and server compromise through SQL queries.
Fronsetiav Cross-Site Scripting Scanner
Targets the 'WSDL Location' parameter in show_operations.jsp, enabling attackers to inject malicious scripts that execute in victims' browsers.
Top 38 Parameters XSS Vulnerability Scanner
Detecting Cross-Site Scripting (XSS) Through Top 38 Parameters
Metabase - Unauthenticated SQL Injection
Metabase contains a sql injection caused by improper sanitization of input in the '/reset_password' database endpoint, letting remote unauthenticated attackers gain administrator access, exploit requires no special privileges.
Loan Management System 1.0 - SQL Injection
Loan Management System 1.0 contains a SQL injection vulnerability via the username parameter. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
Company Visitor Management System 1.0 - SQL Injection
Company Visitor Management System 1.0 contains a SQL injection vulnerability via the login page in the username parameter. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
SiYuan - SQL Execution
SiYuan
Advantech WISE-IoTSuite/SaaS - SQL Injection
Advantech WISE-IoTSuite/SaaS Composer suffers from an unauthenticated SQL Injection vulnerability due to the unsafe use of the `filename` parameter within the URL path in PostgreSQL queries. Remote attackers can exploit this flaw by injecting SQL code (such as the use of `pg_sleep` for time delays) to verify the vulnerability, and may gain further impact such as Remote Code Execution (RCE) depending on the privileges granted to the database user.
Zoo Management System 1.0 - SQL Injection
Zoo Management System 1.0 contains a SQL injection vulnerability via the username parameter on the login page. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
Wuzhicms 4.1.0 - SQL Injection
Wuzhicms 4.1.0 contains a SQL injection vulnerability via the grouppid parameter of /coreframe/app/member/admin/group.php. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
Windmill < 1.603.3 - SQL Injection
Windmill versions 1.276.0 through 1.603.2 contain an authenticated SQL injection vulnerability in the folder owner management endpoint. The addowner API endpoint passes user-supplied input directly into a SQL query without sanitization, enabling JSONB path injection. An authenticated user with operator-level access can extract sensitive data including JWT secrets, password hashes, API tokens, and database credentials, leading to full privilege escalation and remote code execution.
CKAN DataStore SQL Search - SQL Injection
CKAN, an open-source data management system used for powering open data portals, contains an unauthenticated SQL injection vulnerability in the datastore_search_sql API endpoint.
Grandstream UCM6200 - SQL Injection
Grandstream UCM6200 series contains an unauthenticated remote SQL injection caused by crafted HTTP requests, letting attackers execute shell commands as root on versions before 1.0.19.20 or inject HTML in emails before 1.0.20.17.
GeoServer jsonArrayContains CQL Filter - SQL Injection
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoTools FilterToSqlHelper.constructEquality writes the expected argument of the jsonArrayContains CQL function RAW into the SQL string while only escaping the JSON pointer. A single quote in the value parameter breaks out of the PostgreSQL jsonb_path_exists string literal, enabling unauthenticated SQL injection. When the PostGIS backend runs with superuser privileges, the injection escalates to operating system command execution through PostgreSQL COPY TO PROGRAM. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should enable the PostGIS DataStore preparedStatements setting and disable encode functions as a workaround.
ZEROF Web Server 2.0 - SQL Injection
ZEROF Web Server 2.0 allows SQL Injection via the /HandleEvent endpoint. Attackers can exploit this vulnerability by manipulating the request parameters to execute arbitrary SQL queries.
Mingsoft MCMS 5.2.9 - SQL Injection
Mingsoft MCMS v5.2.9 contains a SQL injection caused by unsanitized categoryType parameter at /content/list.do, letting attackers execute arbitrary SQL commands, exploit requires crafted input.
KevinLAB BEMS 1.0 - SQL Injection
KevinLAB BEMS 1.0 contains a SQL injection vulnerability. Input passed through input_id POST parameter in /http/index.php is not properly sanitized before being returned to the user or used in SQL queries. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
phpMyFAQ <= 4.1.1 - SQL Injection
phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/captcha endpoint by crafting malicious User-Agent headers to perform time-based blind SQL injection, extracting sensitive data including user credentials, admin tokens, and SMTP credentials from the database.
XWiki REST API Query - SQL Injection
A SQL injection vulnerability exists in XWiki's REST API query endpoint. An unauthenticated attacker can execute arbitrary SQL queries through the 'q' parameter by manipulating the HQL query, potentially leading to data exfiltration or system compromise.
CVE-2020-15415 Scanner
CVE-2020-15415 Scanner - Command Injection vulnerability in DrayTek Vigor
Django - SQL injection
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.
E-Learning System 1.0 - SQL Injection
E-Learning System 1.0 contains an unauthenticated SQL injection caused by unsanitized input, letting remote attackers execute arbitrary code on the server and gain a reverse shell, exploit requires no authentication.
CVE-2025-22952 Scanner
CVE-2025-22952 Scanner - Server Side Request Forgery vulnerability in Elestio Memos
YesWiki < 4.6.4 - Unauthenticated SQL Injection
YesWiki before version 4.6.4 contains an unauthenticated SQL injection vulnerability in the Bazar form-import path. The bn_id_nature parameter in FormManager::create() is concatenated into an INSERT statement without sanitization, allowing unauthenticated attackers to inject arbitrary SQL and read the full database including password hashes.
PrestaShop lgcookieslaw - SQL Injection
The EU Cookie Law GDPR (Banner + Blocker) PrestaShop module before 2.1.3 allows blind SQL injection via the __lglaw or lgcookieslaw cookie used to store user consent choices.
Fortinet FortiClientEMS 7.4.4 - SQL Injection
Fortinet FortiClientEMS version 7.4.4 and earlier contains an unauthenticated SQL injection vulnerability in the /api/v1/init_consts endpoint. The 'Site' HTTP header value is passed directly into the PostgreSQL search_path without sanitization, allowing remote unauthenticated attackers to inject arbitrary SQL commands. This can lead to information disclosure, database manipulation, or OS command execution when chained with PostgreSQL functions.
Alumni Management System 1.0 - SQL Injection
SourceCodester Alumni Management System 1.0 contains a sql_injection caused by unsanitized input in admin/login.php, letting attackers bypass authentication, exploit requires injection of malicious SQL payload.
XWiki Platform - SQL Injection
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value.
WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass
In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
CVE-2022-28033 Scanner
This scanner detects SQL Injection vulnerabilities in Atom.CMS 2.0 digital assets.
### Arachni ### Command İnjection Scanner
A command injection vulnerability occurs when an attacker is able to pass malicious input to a program and have that input executed as an OS command. This can allow attackers to run operation system-level command execution. Command injection is often possible due to insecure coding practices that do not properly validate or sanitize user input.
CVE-2025-2294 Scanner
CVE-2025-2294 Scanner - Local File Inclusion (LFI) vulnerability in Kubio AI Page Builder
Memos < 0.25.0 - Stored Cross-Site Scripting
An authenticated attacker can upload a specially crafted SVG file containing JavaScript code to Memos versions prior to 0.25.0, leading to a stored cross-site scripting (XSS) vulnerability.
Fortinet FortiWeb - SQL Injection
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPS requests.
ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection
ASUSTOR ADM version 3.1.0.RFQ3 is vulnerable to SQL injection via the album_id parameter in the /photo-gallery/api/album/tree_lists/ endpoint. An attacker can exploit this vulnerability to execute arbitrary SQL commands on the database, potentially leading to information disclosure or further compromise of the affected system.
FreePBX - Remote Code Execution
FreePBX 15, 16, and 17 contain a remote code execution caused by insufficiently sanitized user-supplied data in endpoints, letting unauthenticated attackers manipulate the database and execute code remotely, exploit requires no authentication.
St. Joe ERP system - SQL Injection
A SQL injection vulnerability exists in the St. Joe ERP system ("ERP") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database.
ChurchCRM - SQL Injection
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion.
Mitel MiCollab <= 9.8.0.33 - SQL Injection
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
Code-Projects School Fees Payment System 1.0 - SQL Injection
A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Citrix SD-WAN and NetScaler SD-WAN - SQL Injection
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 contain an SQL injection vulnerability. An unauthenticated attacker can exploit improper validation of input in specific components, which could allow for execution of arbitrary SQL queries against the backend database. This could result in information disclosure, manipulation of data, or complete compromise of affected systems.
Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection
Sangoma Switchvox before version 8.4.0.2 contains an unauthenticated SQL injection vulnerability in the /pa endpoint (PhoneAppsHandler.pm). The PhoneIP field extracted from an XML POST body is concatenated directly into an unparameterized PostgreSQL query that runs as a database superuser. An attacker can break out of the single-quoted SQL string context and leverage PostgreSQL COPY TO PROGRAM to execute arbitrary operating system commands without authentication.
phpMyAdmin < 5.0.3 - SQL Injection
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 contains a SQL injection caused by improper processing of SQL statements in the search feature, letting attackers inject malicious SQL, exploit requires crafted search input.
Run all Web Vulnerabilities checks at once.
S4E covers 294+ scanners in this category with continuous monitoring and full remediation guidance.
Start Free Scan →