Vulnerabilities (CVE)

Filtered by CWE-89
Total 14647 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-6571 1 Mail-masta Project 1 Mail-masta 2025-04-20 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.
CVE-2017-17602 1 Advance B2b Script Project 1 Advance B2b Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
CVE-2017-1000004 1 Atutor 1 Atutor 2025-04-20 7.5 HIGH 9.8 CRITICAL
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Social Group Member Search, Social Friend Search, Social Group Search, File Comment, Gradebook Test Title, User Group Membership, Inbox/Sent Items, Sent Messages, Links, Photo Album, Poll, Social Application, Social Profile, Test, Content Menu, Auto-Login, and Gradebook components resulting in information disclosure, database modification, or potential code execution.
CVE-2016-5952 1 Ibm 1 Kenexa Lcms Premier 2025-04-20 6.5 MEDIUM 8.8 HIGH
IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2017-17583 1 Shutterstock Clone Project 1 Shutterstock Clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
CVE-2017-15379 1 Softwarepublico 1 E-sic 2025-04-20 7.5 HIGH 9.8 CRITICAL
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
CVE-2017-1002028 1 Angrybyte 1 Gallery-transformation 2025-04-20 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.
CVE-2017-15381 1 Softwarepublico 1 E-sic 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
CVE-2017-11161 1 Synology 1 Photo Station 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.
CVE-2017-5345 1 Metalgenix 1 Genixcms 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.
CVE-2017-17110 1 Techno - Portfolio Management Panel Project 1 Techno - Portfolio Management Panel 2025-04-20 7.5 HIGH 9.8 CRITICAL
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
CVE-2017-17823 1 Piwigo 1 Piwigo 2025-04-20 4.0 MEDIUM 4.9 MEDIUM
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2017-12977 1 10web 1 Photo Gallery 2025-04-20 6.5 MEDIUM 7.2 HIGH
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploitable by administrators via the tag_id parameter.
CVE-2014-4914 2 Debian, Zend 2 Debian Linux, Zend Framework 2025-04-20 7.5 HIGH 9.8 CRITICAL
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
CVE-2017-16955 1 Inlinks Project 1 Inlinks 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.php.
CVE-2017-6065 1 Metalgenix 1 Genixcms 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.
CVE-2015-3313 1 Community Events Project 1 Community Events 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
CVE-2016-9994 1 Ibm 1 Kenexa Lcms Premier 2025-04-20 6.5 MEDIUM 7.1 HIGH
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805.
CVE-2017-6576 1 Mail-masta Project 1 Mail-masta 2025-04-20 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter: id.
CVE-2017-1002010 1 Ontraport 1 Membership Simplified 2025-04-20 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function.