Vulnerabilities (CVE)

Filtered by CWE-89
Total 16219 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-43052 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-05 N/A 7.2 HIGH
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete.
CVE-2022-43051 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-05 N/A 7.2 HIGH
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test.
CVE-2022-43049 1 Canteen Management System Project 1 Canteen Management System 2025-05-05 N/A 7.2 HIGH
Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youthappam/add-food.php.
CVE-2022-42990 1 Oretnom23 1 Food Ordering Management System 2025-05-05 N/A 7.2 HIGH
Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all-orders.php?status=Cancelled%20by%20Customer.
CVE-2020-20122 1 Wuzhicms 1 Wuzhicms 2025-05-05 7.5 HIGH 9.8 CRITICAL
Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.
CVE-2018-11528 1 Wuzhicms 1 Wuzhicms 2025-05-05 7.5 HIGH 9.8 CRITICAL
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
CVE-2022-27431 1 Wuzhicms 1 Wuzhicms 2025-05-05 7.5 HIGH 9.8 CRITICAL
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.
CVE-2024-25288 1 Slims 1 Senayan Library Management System 2025-05-05 N/A 4.9 MEDIUM
SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
CVE-2022-21720 1 Glpi-project 1 Glpi 2025-05-05 4.0 MEDIUM 4.9 MEDIUM
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability.
CVE-2022-1505 1 Carrcommunications 1 Rsvpmaker 2025-05-05 5.0 MEDIUM 9.8 CRITICAL
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6.
CVE-2022-1453 1 Carrcommunications 1 Rsvpmaker 2025-05-05 5.0 MEDIUM 9.8 CRITICAL
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.
CVE-2023-27167 1 Supremainc 1 Biostar 2 2025-05-05 N/A 6.5 MEDIUM
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.
CVE-2022-43126 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-05 N/A 7.2 HIGH
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/tests/manage_test.php.
CVE-2022-43125 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-05 N/A 7.2 HIGH
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php.
CVE-2022-43124 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-05 N/A 7.2 HIGH
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.
CVE-2022-43086 1 Codeastro 1 Restaurant Pos System 2025-05-05 N/A 4.9 MEDIUM
Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.
CVE-2025-0410 1 Liujianview 1 Gymxmjpa 2025-05-05 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in liujianview gymxmjpa 1.0. This vulnerability affects the function MenberDaoInpl of the file src/main/java/com/liujian/gymxmjpa/controller/MenberConntroller.java. The manipulation of the argument hyname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-0409 1 Liujianview 1 Gymxmjpa 2025-05-05 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in liujianview gymxmjpa 1.0. This affects the function MembertypeDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/MembertypeController.java. The manipulation of the argument typeName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-0408 1 Liujianview 1 Gymxmjpa 2025-05-05 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in liujianview gymxmjpa 1.0. It has been rated as critical. Affected by this issue is the function LoosDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/LoosController.java. The manipulation of the argument loosName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-0407 1 Liujianview 1 Gymxmjpa 2025-05-05 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in liujianview gymxmjpa 1.0. It has been declared as critical. Affected by this vulnerability is the function EquipmentDaoImpl of the file src/main/java/com/liujian/gymxmjpa/controller/EquipmentController.java. The manipulation of the argument hyname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.