PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
294 tools·Free, no account required

Web Vulnerability Scanners

Web vulnerability scanners test HTTP/HTTPS endpoints for injection flaws, broken authentication, sensitive data exposure, and logic errors. Use these tools to continuously monitor your public-facing applications before attackers do.

By the numbers
294
Web Vulnerabilities scanners
in this category
782.8k
Automated runs
scans executed here
118
Assets scanned
verified across S4E
Newestcve-search 4.0-6.0.0 - Unauthenticated NoSQL Injection
Run Full Scan →← All categories
Network VulnerabilitiesMisconfigurationInformation ScansExposed PanelsProduct CVEs (Web)Product CVEs (Network)DNS ControlsSSL Controls
Featured in this category

Important Web Vulnerabilities Scanners

Browse all 294 tools →
high7.3

Online Generic SQL Injection Vulnerability Scanner

Detect SQL Injection vulnerabilities in your web applications

~1800sSingle assetBulk scanAPI
Nov 16, 2021
medium6.1

Free and Online Generic XSS Scanner

XSS Vulnerability is a type of vulnerability typically found in web applications. It occurs when user input data is not correctly filtered or sanitized before being returned to the end-user.

~60sSingle assetBulk scanAPI
Mar 24, 2022
high7.3

Generic SSRF Vulnerability Scanner

Server-side request forgery (SSRF), is a vulnerability that allows an attacker to execute unauthorized requests from the perspective of the webserver. SSRF can be used to access sensitive data, such as internal network resources and user data, or to launch attacks on other systems from the webserver.The impact of SSRF attacks can be significant. They can allow attackers to arbitrary command execution, access internal apps, and even scan ports in the local network.

~10sSingle assetAPI
Mar 24, 2022
high8.6

Generic Server Side Template Injection (SSTI) Vulnerability Scanner

Detects 'Server Side Template Injection (SSTI)' vulnerability in Web Application. Identifies injectable template contexts that allow server-side evaluation of attacker-controlled expressions, enabling data exposure or remote code execution if exploited.

~300sSingle assetBulk scanAPI
Nov 5, 2025
high7.3

Online Generic File Inclusion - LFI/RFI Vulnerability Scanner

File inclusion vulnerabilities are a type of vulnerability that occurs when an attacker is able to include a file, usually through using inputs on the webserver. These vulnerabilities can lead to information disclosure, arbitrary code execution, and full system compromise.

~10sSingle assetAPI
Mar 24, 2022
high8.0

Generic Blind XXE Scanner

Generic Blind XXE Scanner

~10sSingle assetAPI
Jan 15, 2022
critical9.8

Generic Command Injection Vulnerability Scanner

A command injection vulnerability occurs when an attacker is able to pass malicious input to a program and have that input executed as an OS command. This can allow attackers to run operation system-level command execution. Command injection is often possible due to insecure coding practices that do not properly validate or sanitize user input.

~60sSingle assetBulk scanAPI
Mar 24, 2022
critical10.0

HTTP Header Command Injection Vulnerability Fuzz & Scanner

You can fuzz HTTP headers for command injection using this tool.

~300sSingle assetAPI
May 14, 2021
high8.0

Cache Poisoning to Stored XSS Vulnerability Scanner

This scanner identifies vulnerabilities where cache poisoning could lead to stored XSS, enabling attackers to inject malicious scripts that are executed when the cached content is served.

~60sSingle assetAPI
Feb 12, 2024
medium6.5

### Arachni ### Web Application Source Code Disclosure Scanner

Detects 'Source Code Disclosure' vulnerability in Web Application affecting exposed source/config files and repository artifacts. This scanner finds accessible source files, backups, and repository metadata that may reveal sensitive code and secrets.

~10sSingle assetAPI
Oct 16, 2025
critical9.8

### Arachni ### Generic Code Injection Vulnerability Scanner

Detects 'Code Injection' vulnerability. This scanner identifies weaknesses in web applications, built with technologies like PHP, Ruby, Python, Java, and ASP, where an attacker can introduce and execute arbitrary code. Detecting this critical flaw prevents unauthorized server access and potential system compromise.

~10sSingle assetBulk scanAPI
Oct 16, 2025
critical9.0

Halo ITSM SQL Injection Scanner

Detects 'SQL Injection' vulnerability in Halo ITSM.

~60sSingle assetAPI
Apr 4, 2025
high8.1

Windows LFI Vulnerability Scanner

Detect and Protect Against Windows LFI Vulnerabilities

~15sSingle assetAPI
May 14, 2021
high8.1

Generic Linux LFI Detection Scanner

Identify and Mitigate Local File Inclusion Vulnerabilities in Linux Systems

~15sSingle assetAPI
May 14, 2021
high8.0

J2EE LFI Vulnerability Scanner

Detect potential Local File Inclusion (LFI) vulnerabilities within J2EE applications, focusing on unauthorized access to critical files such as web.xml, which could lead to sensitive information disclosure.

~60sSingle assetAPI
Feb 12, 2024
high8.0

CPAS Management System SQL Injection Scanner

Detects 'SQL Injection' vulnerability in CPAS Management System affects v. 4. This scanner identifies critical flaws allowing unauthorized data retrieval and server compromise through SQL queries.

~60sSingle assetBulk scanAPI
Jan 7, 2025
high8.3

Fronsetiav Cross-Site Scripting Scanner

Targets the 'WSDL Location' parameter in show_operations.jsp, enabling attackers to inject malicious scripts that execute in victims' browsers.

~10sSingle assetAPI
Dec 1, 2024
high7.4

Top 38 Parameters XSS Vulnerability Scanner

Detecting Cross-Site Scripting (XSS) Through Top 38 Parameters

~60sSingle assetAPI
Feb 12, 2024
critical10.0

Metabase - Unauthenticated SQL Injection

Metabase contains a sql injection caused by improper sanitization of input in the '/reset_password' database endpoint, letting remote unauthenticated attackers gain administrator access, exploit requires no special privileges.

~10sBulk scanAPI
Aug 12, 2026
critical10.0

Loan Management System 1.0 - SQL Injection

Loan Management System 1.0 contains a SQL injection vulnerability via the username parameter. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

~10sAPI
Oct 15, 2025
critical10.0

Company Visitor Management System 1.0 - SQL Injection

Company Visitor Management System 1.0 contains a SQL injection vulnerability via the login page in the username parameter. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

~10sAPI
Oct 15, 2025
critical10.0

SiYuan - SQL Execution

SiYuan

~10sBulk scanAPI
Aug 18, 2026
critical10.0

Advantech WISE-IoTSuite/SaaS - SQL Injection

Advantech WISE-IoTSuite/SaaS Composer suffers from an unauthenticated SQL Injection vulnerability due to the unsafe use of the `filename` parameter within the URL path in PostgreSQL queries. Remote attackers can exploit this flaw by injecting SQL code (such as the use of `pg_sleep` for time delays) to verify the vulnerability, and may gain further impact such as Remote Code Execution (RCE) depending on the privileges granted to the database user.

~10sBulk scanAPI
Jan 22, 2026
critical10.0

Zoo Management System 1.0 - SQL Injection

Zoo Management System 1.0 contains a SQL injection vulnerability via the username parameter on the login page. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

~10sAPI
Oct 15, 2025
critical10.0

Wuzhicms 4.1.0 - SQL Injection

Wuzhicms 4.1.0 contains a SQL injection vulnerability via the grouppid parameter of /coreframe/app/member/admin/group.php. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

~10sAPI
Oct 15, 2025
critical9.9

Windmill < 1.603.3 - SQL Injection

Windmill versions 1.276.0 through 1.603.2 contain an authenticated SQL injection vulnerability in the folder owner management endpoint. The addowner API endpoint passes user-supplied input directly into a SQL query without sanitization, enabling JSONB path injection. An authenticated user with operator-level access can extract sensitive data including JWT secrets, password hashes, API tokens, and database credentials, leading to full privilege escalation and remote code execution.

~10sBulk scanAPI
Aug 2, 2026
critical9.8

CKAN DataStore SQL Search - SQL Injection

CKAN, an open-source data management system used for powering open data portals, contains an unauthenticated SQL injection vulnerability in the datastore_search_sql API endpoint.

~10sBulk scanAPI
May 5, 2026
critical9.8

Grandstream UCM6200 - SQL Injection

Grandstream UCM6200 series contains an unauthenticated remote SQL injection caused by crafted HTTP requests, letting attackers execute shell commands as root on versions before 1.0.19.20 or inject HTML in emails before 1.0.20.17.

~10sBulk scanAPI
Jan 21, 2026
critical9.8

GeoServer jsonArrayContains CQL Filter - SQL Injection

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoTools FilterToSqlHelper.constructEquality writes the expected argument of the jsonArrayContains CQL function RAW into the SQL string while only escaping the JSON pointer. A single quote in the value parameter breaks out of the PostgreSQL jsonb_path_exists string literal, enabling unauthenticated SQL injection. When the PostGIS backend runs with superuser privileges, the injection escalates to operating system command execution through PostgreSQL COPY TO PROGRAM. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should enable the PostGIS DataStore preparedStatements setting and disable encode functions as a workaround.

~10sBulk scanAPI
Aug 25, 2026
critical9.8

ZEROF Web Server 2.0 - SQL Injection

ZEROF Web Server 2.0 allows SQL Injection via the /HandleEvent endpoint. Attackers can exploit this vulnerability by manipulating the request parameters to execute arbitrary SQL queries.

~10sAPI
Sep 24, 2025
critical9.8

Mingsoft MCMS 5.2.9 - SQL Injection

Mingsoft MCMS v5.2.9 contains a SQL injection caused by unsanitized categoryType parameter at /content/list.do, letting attackers execute arbitrary SQL commands, exploit requires crafted input.

~10sAPI
Oct 8, 2025
critical9.8

KevinLAB BEMS 1.0 - SQL Injection

KevinLAB BEMS 1.0 contains a SQL injection vulnerability. Input passed through input_id POST parameter in /http/index.php is not properly sanitized before being returned to the user or used in SQL queries. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

~10sAPI
Oct 8, 2025
critical9.8

phpMyFAQ <= 4.1.1 - SQL Injection

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/captcha endpoint by crafting malicious User-Agent headers to perform time-based blind SQL injection, extracting sensitive data including user credentials, admin tokens, and SMTP credentials from the database.

~10sBulk scanAPI
Jun 11, 2026
critical9.8

XWiki REST API Query - SQL Injection

A SQL injection vulnerability exists in XWiki's REST API query endpoint. An unauthenticated attacker can execute arbitrary SQL queries through the 'q' parameter by manipulating the HQL query, potentially leading to data exfiltration or system compromise.

~10sAPI
Aug 29, 2025
critical9.8

CVE-2020-15415 Scanner

CVE-2020-15415 Scanner - Command Injection vulnerability in DrayTek Vigor

~10sSingle assetAPI
May 19, 2025
critical9.8

Django - SQL injection

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

~10sAPI
Nov 5, 2025
critical9.8

E-Learning System 1.0 - SQL Injection

E-Learning System 1.0 contains an unauthenticated SQL injection caused by unsanitized input, letting remote attackers execute arbitrary code on the server and gain a reverse shell, exploit requires no authentication.

~10sBulk scanAPI
Jun 3, 2026
critical9.8

CVE-2025-22952 Scanner

CVE-2025-22952 Scanner - Server Side Request Forgery vulnerability in Elestio Memos

~60sSingle assetAPI
Mar 4, 2025
critical9.8

YesWiki < 4.6.4 - Unauthenticated SQL Injection

YesWiki before version 4.6.4 contains an unauthenticated SQL injection vulnerability in the Bazar form-import path. The bn_id_nature parameter in FormManager::create() is concatenated into an INSERT statement without sanitization, allowing unauthenticated attackers to inject arbitrary SQL and read the full database including password hashes.

~10sBulk scanAPI
May 27, 2026
critical9.8

PrestaShop lgcookieslaw - SQL Injection

The EU Cookie Law GDPR (Banner + Blocker) PrestaShop module before 2.1.3 allows blind SQL injection via the __lglaw or lgcookieslaw cookie used to store user consent choices.

~10sBulk scanAPI
Jun 8, 2026
critical9.8

Fortinet FortiClientEMS 7.4.4 - SQL Injection

Fortinet FortiClientEMS version 7.4.4 and earlier contains an unauthenticated SQL injection vulnerability in the /api/v1/init_consts endpoint. The 'Site' HTTP header value is passed directly into the PostgreSQL search_path without sanitization, allowing remote unauthenticated attackers to inject arbitrary SQL commands. This can lead to information disclosure, database manipulation, or OS command execution when chained with PostgreSQL functions.

~10sBulk scanAPI
Apr 9, 2026
critical9.8

Alumni Management System 1.0 - SQL Injection

SourceCodester Alumni Management System 1.0 contains a sql_injection caused by unsanitized input in admin/login.php, letting attackers bypass authentication, exploit requires injection of malicious SQL payload.

~10sAPI
Oct 8, 2025
critical9.8

XWiki Platform - SQL Injection

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value.

~10sAPI
Nov 4, 2025
critical9.8

WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

~10sBulk scanAPI
Feb 4, 2026
critical9.8

CVE-2022-28033 Scanner

This scanner detects SQL Injection vulnerabilities in Atom.CMS 2.0 digital assets.

~10sSingle assetAPI
Nov 6, 2024
critical9.8

### Arachni ### Command İnjection Scanner

A command injection vulnerability occurs when an attacker is able to pass malicious input to a program and have that input executed as an OS command. This can allow attackers to run operation system-level command execution. Command injection is often possible due to insecure coding practices that do not properly validate or sanitize user input.

~10sSingle assetAPI
Jul 16, 2025
critical9.8

CVE-2025-2294 Scanner

CVE-2025-2294 Scanner - Local File Inclusion (LFI) vulnerability in Kubio AI Page Builder

~10sSingle assetAPI
Apr 16, 2025
critical9.8

Memos < 0.25.0 - Stored Cross-Site Scripting

An authenticated attacker can upload a specially crafted SVG file containing JavaScript code to Memos versions prior to 0.25.0, leading to a stored cross-site scripting (XSS) vulnerability.

~10sAPI
Sep 6, 2025
critical9.8

Fortinet FortiWeb - SQL Injection

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPS requests.

~10sAPI
Aug 5, 2025
critical9.8

ASUSTOR ADM 3.1.0.RFQ3 - SQL Injection

ASUSTOR ADM version 3.1.0.RFQ3 is vulnerable to SQL injection via the album_id parameter in the /photo-gallery/api/album/tree_lists/ endpoint. An attacker can exploit this vulnerability to execute arbitrary SQL commands on the database, potentially leading to information disclosure or further compromise of the affected system.

~10sAPI
Oct 6, 2025
critical9.8

FreePBX - Remote Code Execution

FreePBX 15, 16, and 17 contain a remote code execution caused by insufficiently sanitized user-supplied data in endpoints, letting unauthenticated attackers manipulate the database and execute code remotely, exploit requires no authentication.

~10sAPI
Sep 11, 2025
critical9.8

St. Joe ERP system - SQL Injection

A SQL injection vulnerability exists in the St. Joe ERP system ("ERP") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database.

~10sAPI
Oct 19, 2025
critical9.8

ChurchCRM - SQL Injection

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion.

~10sAPI
Nov 5, 2025
critical9.8

Mitel MiCollab <= 9.8.0.33 - SQL Injection

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

~10sAPI
Oct 12, 2025
critical9.8

Code-Projects School Fees Payment System 1.0 - SQL Injection

A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

~10sAPI
Nov 3, 2025
critical9.8

Citrix SD-WAN and NetScaler SD-WAN - SQL Injection

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 contain an SQL injection vulnerability. An unauthenticated attacker can exploit improper validation of input in specific components, which could allow for execution of arbitrary SQL queries against the backend database. This could result in information disclosure, manipulation of data, or complete compromise of affected systems.

~10sAPI
Oct 23, 2025
critical9.8

Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection

Sangoma Switchvox before version 8.4.0.2 contains an unauthenticated SQL injection vulnerability in the /pa endpoint (PhoneAppsHandler.pm). The PhoneIP field extracted from an XML POST body is concatenated directly into an unparameterized PostgreSQL query that runs as a database superuser. An attacker can break out of the single-quoted SQL string context and leverage PostgreSQL COPY TO PROGRAM to execute arbitrary operating system commands without authentication.

~10sBulk scanAPI
Sep 2, 2026
critical9.8

phpMyAdmin < 5.0.3 - SQL Injection

phpMyAdmin before 4.9.6 and 5.x before 5.0.3 contains a SQL injection caused by improper processing of SQL statements in the search feature, letting attackers inject malicious SQL, exploit requires crafted search input.

~10sBulk scanAPI
Jan 21, 2026

Run all Web Vulnerabilities checks at once.

S4E covers 294+ scanners in this category with continuous monitoring and full remediation guidance.

Start Free Scan →