Vulnerabilities (CVE)

Filtered by CWE-89
Total 19913 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16846 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
CVE-2017-16735 1 Ecava 1 Integraxor 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which generates an error in the database log.
CVE-2017-16733 1 Ecava 1 Integraxor 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can leverage to disclose sensitive information from the database.
CVE-2017-16716 1 Advantech 1 Webaccess 2026-06-17 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.
CVE-2017-16561 1 Ingenious School Management System Project 1 Ingenious School Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
/view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request.
CVE-2017-16558 1 Contao 1 Contao Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
CVE-2017-16543 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
CVE-2017-16542 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
CVE-2017-16510 1 Wordpress 1 Wordpress 2026-06-17 7.5 HIGH 9.8 CRITICAL
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
CVE-2017-16000 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the graph parameter to module/capacity_per_label/index.php.
CVE-2017-15993 1 Zomato Clone Script Project 1 Zomato Clone Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
CVE-2017-15992 1 Website Broker Script Project 1 Website Broker Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
CVE-2017-15991 1 Vastal 1 Agent Zone 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951, CVE-2009-3497, and CVE-2012-0982.
CVE-2017-15989 1 Online Exam Test Application Project 1 Online Exam Test Application 2026-06-17 7.5 HIGH 9.8 CRITICAL
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
CVE-2017-15988 1 Nicephpscripts 1 Nice Php Faq Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.
CVE-2017-15987 1 Fake Magazine Cover Script Project 1 Fake Magazine Cover Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.
CVE-2017-15986 1 Cpa Lead Reward Script Project 1 Cpa Lead Reward Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
CPA Lead Reward Script allows SQL Injection via the username parameter.
CVE-2017-15985 1 Readymadeb2bscript 1 Basic B2b Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
CVE-2017-15984 1 Bekirk 1 Creative Management System Lite 2026-06-17 7.5 HIGH 9.8 CRITICAL
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
CVE-2017-15983 1 Geniusocean 1 Mymagazine Magazine \& Blog Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.