Vulnerabilities (CVE)

Filtered by CWE-89
Total 19969 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-27984 1 Cuppacms 1 Cuppacms 2026-07-09 7.5 HIGH 9.8 CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
CVE-2022-24240 1 Aceware 1 Aceweb Online Portal 2026-07-09 7.5 HIGH 9.8 CRITICAL
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
CVE-2021-45811 1 Enhancesoft 1 Osticket 2026-07-09 N/A 6.5 MEDIUM
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
CVE-2021-44088 1 Attendance And Payroll System Project 1 Attendance And Payroll System 2026-07-09 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
CVE-2021-42633 1 Printerlogic 1 Web Stack 2026-07-09 5.0 MEDIUM 5.3 MEDIUM
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.
CVE-2021-41672 1 Peel 1 Peel Shopping 2026-07-09 5.5 MEDIUM 6.5 MEDIUM
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retrive information from the database.
CVE-2021-3262 1 Trispark 2 Novusedu, Veo Transportation 2026-07-09 N/A 9.8 CRITICAL
TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries.
CVE-2021-29053 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 6.5 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) CommerceChannelRelFinder.findByC_C.
CVE-2021-29004 1 Rconfig 1 Rconfig 2026-07-09 6.5 MEDIUM 8.8 HIGH
rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the server and access it remotely.
CVE-2021-28993 1 Plixer 1 Scrutinizer 2026-07-09 5.0 MEDIUM 7.5 HIGH
Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).
CVE-2021-25874 1 Youphptube 1 Youphptube 2026-07-09 5.0 MEDIUM 7.5 HIGH
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.
CVE-2020-35276 1 Egavilanmedia 1 Ecm Address Book 2026-07-09 7.5 HIGH 9.8 CRITICAL
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
CVE-2020-29228 1 Egavilanmedia 1 User Registration And Login System With Admin Panel 2026-07-09 5.0 MEDIUM 7.5 HIGH
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
CVE-2020-28860 1 Openasset 1 Digital Asset Management 2026-07-09 6.5 MEDIUM 8.8 HIGH
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
CVE-2020-26677 1 Vfairs 1 Vfairs 2026-07-09 6.5 MEDIUM 8.8 HIGH
Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
CVE-2020-26625 1 Gilacms 1 Gila Cms 2026-07-09 N/A 3.8 LOW
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.
CVE-2020-26624 1 Gilacms 1 Gila Cms 2026-07-09 N/A 3.8 LOW
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
CVE-2020-26623 1 Gilacms 1 Gila Cms 2026-07-09 N/A 3.8 LOW
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
CVE-2020-25514 1 Simple Library Management System Project 1 Simple Library Management System 2026-07-09 4.6 MEDIUM 8.4 HIGH
Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://<site>/lms/admin.php.
CVE-2020-25487 1 Phpgurukul 1 Zoo Management System 2026-07-09 4.6 MEDIUM 7.8 HIGH
PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.