Vulnerabilities (CVE)

Filtered by CWE-89
Total 20121 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-21665 1 Fastadmin 1 Fastadmin 2026-06-17 6.5 MEDIUM 7.2 HIGH
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
CVE-2020-21662 1 Yunyecms 1 Yunyecms 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.
CVE-2020-21486 1 Phpok 1 Phpok 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
CVE-2020-21400 1 Phpmywind 1 Phpmywind 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.
CVE-2020-21394 1 Crmeb 1 Crmeb 2026-06-17 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
CVE-2020-21378 1 Seacms 1 Seacms 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
CVE-2020-21377 1 Yunyecms 1 Yunyecms 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.
CVE-2020-21250 1 Cszcms 1 Csz Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
CVE-2020-21180 1 Koa2-blog Project 1 Koa2-blog 2026-06-17 7.5 HIGH 9.8 CRITICAL
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.
CVE-2020-21179 1 Koa2-blog Project 1 Koa2-blog 2026-06-17 7.5 HIGH 9.8 CRITICAL
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signin page.
CVE-2020-21176 1 Thinkjs 1 Thinkjs 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
CVE-2020-21152 1 Inxedu 1 Inxedu 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
CVE-2020-21133 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.
CVE-2020-21132 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.
CVE-2020-21131 1 Metinfo 1 Metinfo 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.
CVE-2020-21127 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
CVE-2020-21121 1 Kliqqi 1 Kliqqi Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.
CVE-2020-21120 1 Uqcms 1 Uqcms 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.
CVE-2020-21119 1 Kliqqi 1 Kliqqi Cms 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.
CVE-2020-21060 1 Phpmywind 1 Phpmywind 2026-06-17 N/A 8.8 HIGH
SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page.