Vulnerabilities (CVE)

Filtered by CWE-89
Total 19943 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14592 1 Cwjoomla 2 Cw Article Attachments Free, Cw Article Attachments Pro 2026-06-17 7.5 HIGH 9.8 CRITICAL
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
CVE-2018-14515 1 Wuzhi Cms Project 1 Wuzhi Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
A SQL injection was discovered in WUZHI CMS 4.1.0 that allows remote attackers to inject a malicious SQL statement via the index.php?m=promote&f=index&v=search keywords parameter.
CVE-2018-14502 1 Kibokolabs 1 Chained Quiz 2026-06-17 7.5 HIGH 9.8 CRITICAL
controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters.
CVE-2018-14501 1 Joyplus Project 1 Joyplus-cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring.
CVE-2018-14472 1 Wuzhicms 1 Wuzhicms 2026-06-17 6.5 MEDIUM 7.2 HIGH
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.
CVE-2018-14440 1 Ssh Companywebsite Project 1 Ssh Companywebsite 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
CVE-2018-14418 1 Msvod 1 Msvod Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
CVE-2018-14389 1 Joyplus-cms Project 1 Joyplus-cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
CVE-2018-14066 3 Google, Infinixmobility, Lenovo 3 Android, Infinix X571, Lenovo A7020 2026-06-17 7.5 HIGH 9.8 CRITICAL
The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.
CVE-2018-14058 1 Pimcore 1 Pimcore 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
CVE-2018-14012 1 Wolfsight 1 Wolfsight Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI.
CVE-2018-13850 1 Icanstudioz 1 Firebase Push Notification On Ios \/ Fcm \+ Advance Admin Panel 2026-06-17 7.5 HIGH 9.8 CRITICAL
The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter.
CVE-2018-13824 2 Broadcom, Ca 2 Project Portfolio Management, Project Portfolio Management 2026-06-17 7.5 HIGH 9.8 CRITICAL
Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks.
CVE-2018-13792 1 Abbyy 1 Flexicapture 2026-06-17 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter.
CVE-2018-13450 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the status_batch parameter.
CVE-2018-13449 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut_buy parameter.
CVE-2018-13448 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter.
CVE-2018-13447 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut parameter.
CVE-2018-13442 1 Solarwinds 1 Network Performance Monitor 2026-06-17 6.5 MEDIUM 8.8 HIGH
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
CVE-2018-13350 1 Terra-master 1 Terramaster Operating System 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.