Total
19890 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-25676 | 1 Phpscriptsmall | 1 Ask Expert Script | 2026-07-24 | N/A | 8.2 HIGH |
| Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in list-details.php to execute arbitrary code or extract database information. | |||||
| CVE-2019-25663 | 1 Salesagility | 1 Suitecrm | 2026-07-24 | N/A | 7.1 HIGH |
| SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information. | |||||
| CVE-2019-25702 | 1 Marmotech | 1 Kados | 2026-07-24 | N/A | 8.2 HIGH |
| Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database information or modify data. | |||||
| CVE-2019-25688 | 1 Marmotech | 1 Kados | 2026-07-24 | N/A | 8.2 HIGH |
| Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive database information or modify database contents. | |||||
| CVE-2019-25674 | 1 Victoralagwu | 1 Cmssite | 2026-07-24 | N/A | 8.2 HIGH |
| CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database information or perform time-based blind SQL injection attacks. | |||||
| CVE-2019-25698 | 1 Marmotech | 1 Kados | 2026-07-24 | N/A | 8.2 HIGH |
| Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive database information. | |||||
| CVE-2019-25668 | 1 Phpscriptsmall | 1 News Website Script | 2026-07-24 | N/A | 8.2 HIGH |
| News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information. | |||||
| CVE-2026-27834 | 1 Piwigo | 1 Piwigo | 2026-07-24 | N/A | 7.2 HIGH |
| Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing authenticated administrators to execute arbitrary SQL commands. This issue has been patched in version 16.3.0. | |||||
| CVE-2019-25694 | 1 Marmotech | 1 Kados | 2026-07-24 | N/A | 8.2 HIGH |
| Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted requests with malicious SQL payloads to extract sensitive database information or modify data. | |||||
| CVE-2019-25696 | 1 Marmotech | 1 Kados | 2026-07-24 | N/A | 8.2 HIGH |
| Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify data. | |||||
| CVE-2019-25684 | 1 Opendocman | 1 Opendocman | 2026-07-24 | N/A | 8.2 HIGH |
| OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information. | |||||
| CVE-2026-34612 | 1 Kestra | 1 Kestra | 2026-07-24 | N/A | 9.9 CRITICAL |
| Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the following endpoint "GET /api/v1/main/flows/search". Once a user is authenticated, simply visiting a crafted link is enough to trigger the vulnerability. The injected payload is executed by PostgreSQL using COPY ... TO PROGRAM ..., which in turn runs arbitrary OS commands on the host. This issue has been patched in version 1.3.7. | |||||
| CVE-2019-25669 | 1 Qdpm | 1 Qdpm | 2026-07-24 | N/A | 8.2 HIGH |
| qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by_extrafields[] values to trigger SQL syntax errors and extract database information. | |||||
| CVE-2019-25675 | 1 Arcasolutions | 1 Edirectory | 2026-07-24 | N/A | 8.2 HIGH |
| eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to authenticate as administrator, then leverage authenticated file disclosure vulnerabilities in language_file.php to read arbitrary PHP files from the server. | |||||
| CVE-2026-27885 | 1 Piwigo | 1 Piwigo | 2026-07-24 | N/A | 7.2 HIGH |
| Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the database, including user credentials, email addresses, and all stored content. This issue has been patched in version 16.3.0. | |||||
| CVE-2019-25672 | 1 Kartatopia | 1 Piluscart | 2026-07-24 | N/A | 8.2 HIGH |
| PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information. | |||||
| CVE-2019-25690 | 1 Marmotech | 1 Kados | 2026-07-24 | N/A | 8.2 HIGH |
| Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database information. | |||||
| CVE-2026-34934 | 1 Praison | 1 Praisonai | 2026-07-24 | N/A | 9.8 CRITICAL |
| PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with unescaped thread IDs fetched from the database. An attacker stores a malicious thread ID via update_thread. When the application loads the thread list, the injected payload executes and grants full database access. This issue has been patched in version 4.5.90. | |||||
| CVE-2019-25662 | 1 Montala | 1 Resourcespace | 2026-07-24 | N/A | 8.2 HIGH |
| ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' parameter. Attackers can send GET requests to the watched_searches.php endpoint with crafted SQL payloads to extract sensitive database information including usernames and credentials. | |||||
| CVE-2026-27634 | 1 Piwigo | 1 Piwigo | 2026-07-24 | N/A | 9.8 CRITICAL |
| Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenated directly into SQL without any escaping or type validation. This could result in an unauthenticated attacker reading the full database, including user password hashes. This issue has been patched in version 16.3.0. | |||||
