Vulnerabilities (CVE)

Filtered by CWE-89
Total 14648 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-6050 1 Ecava 1 Integraxor 2025-04-20 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.
CVE-2017-7221 1 Opentext 1 Documentum Content Server 2025-04-20 6.5 MEDIUM 8.8 HIGH
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by use of a backspace character in an injected string. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513.
CVE-2017-17617 1 Foodspotting Clone Script Project 1 Foodspotting Clone Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
CVE-2017-15971 1 Softdatepro 1 Same Date Pro 2025-04-20 7.5 HIGH 9.8 CRITICAL
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.
CVE-2017-17590 1 Stackoverflow-clone Project 1 Stackoverflow-clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
CVE-2015-2147 1 Phpbugtracker Project 1 Phpbugtracker 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.
CVE-2017-15973 1 Sokial 1 Sokial 2025-04-20 7.5 HIGH 9.8 CRITICAL
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.
CVE-2017-17623 1 Opensource Classified Ads Script Project 1 Opensource Classified Ads Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
CVE-2017-17920 1 Rubyonrails 1 Ruby On Rails 2025-04-20 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
CVE-2015-7346 1 Zcms Project 1 Zcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in ZCMS 1.1.
CVE-2017-7410 1 Websitebaker 1 Websitebaker 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter.
CVE-2015-7517 1 Labwebdesigns 1 Double Opt-in For Download 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.
CVE-2017-14145 1 Helpdezk 1 Helpdezk 2025-04-20 7.5 HIGH 9.8 CRITICAL
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.
CVE-2017-9759 1 Zenbership 1 Zenbership 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL Injection exists in admin/index.php in Zenbership 1.0.8 via the filters array parameter, exploitable by a privileged account.
CVE-2017-16735 1 Ecava 1 Integraxor 2025-04-20 5.0 MEDIUM 5.3 MEDIUM
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which generates an error in the database log.
CVE-2017-7290 1 Xoops 1 Xoops 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.
CVE-2017-17624 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2025-04-20 7.5 HIGH 9.8 CRITICAL
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
CVE-2017-5575 1 Metalgenix 1 Genixcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter.
CVE-2017-6089 1 Phpcollab 1 Phpcollab 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to calendar/deletecalendar.php.
CVE-2017-16543 1 Zohocorp 1 Manageengine Applications Manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.