EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.
- https://github.com/3xxx/engineercms/issues/91
No PoCs found on GitHub currently.