Vulnerabilities (CVE)

Filtered by CWE-89
Total 14647 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9226 1 Alegrocart 1 Alegrocart 2025-04-20 6.5 MEDIUM 7.2 HIGH
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote authenticated users with a valid Paypal transaction token to execute arbitrary SQL commands via the ref parameter in the (3) orderUpdate function in upload/catalog/extension/payment/paypal.php.
CVE-2017-12302 1 Cisco 1 Unified Communications Domain Manager 2025-04-20 4.0 MEDIUM 4.3 MEDIUM
A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The vulnerability is due to a lack of input validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected system. An exploit could allow the attacker to determine the presence of certain values in the database. Cisco Bug IDs: CSCvf36682.
CVE-2017-17643 1 Lynda Clone Project 1 Lynda Clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
CVE-2017-1002009 1 Ontraport 1 Membership Simplified 2025-04-20 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.
CVE-2017-17983 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2025-04-20 6.5 MEDIUM 8.8 HIGH
PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter.
CVE-2017-15378 1 Softwarepublico 1 E-sic 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
CVE-2016-9992 1 Ibm 1 Kenexa Lcms Premier 2025-04-20 6.5 MEDIUM 7.1 HIGH
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067.
CVE-2017-17608 1 Kindergarten - Elementary School Listing Script Project 1 Kindergarten - Elementary School Listing Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Child Care Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-12650 1 Loginizer 1 Loginizer 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
CVE-2017-14238 1 Dolibarr 1 Dolibarr 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.
CVE-2017-5519 1 Metalgenix 1 Genixcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2017-17103 1 Fiyo 1 Fiyo Cms 2025-04-20 6.5 MEDIUM 8.8 HIGH
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.
CVE-2017-11419 1 Fiyo 1 Fiyo Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].
CVE-2017-12949 1 Podlove 1 Podlove Podcast Publisher 2025-04-20 6.5 MEDIUM 8.8 HIGH
lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.
CVE-2017-14703 1 Cashbackcomparisonscript 1 Cash Back Comparison 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.
CVE-2015-6028 1 Castlerock 1 Snmpc 2025-04-20 6.5 MEDIUM 8.8 HIGH
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
CVE-2017-1000120 1 Frappe 1 Frappe 2025-04-20 6.5 MEDIUM 8.8 HIGH
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.
CVE-2017-12585 1 Slims 1 Akasia 2025-04-20 6.5 MEDIUM 8.8 HIGH
SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.
CVE-2017-17628 1 Responsive Realestate Script Project 1 Responsive Realestate Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
CVE-2017-5574 1 Metalgenix 1 Genixcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.