Vulnerabilities (CVE)

Filtered by CWE-89
Total 19913 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15329 1 Huawei 2 Uma, Uma Firmware 2026-06-17 6.5 MEDIUM 8.8 HIGH
Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on HTTP requests that contain user-supplied input, successful exploitation may allow the attacker to execute arbitrary SQL queries.
CVE-2017-15081 1 Phpsugar 1 Php Melody 2026-06-17 7.5 HIGH 9.8 CRITICAL
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
CVE-2017-14960 1 Opentext 1 Document Sciences Xpression 2026-06-17 5.0 MEDIUM 7.5 HIGH
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.
CVE-2017-14851 1 Orpak 1 Siteomat 2026-06-17 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.
CVE-2017-14848 1 Dasinfomedia 1 Wphrm Human Resource Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
CVE-2017-14847 1 Dasinfomedia 1 Wpams Apartment Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14846 1 Dasinfomedia 1 Hospital Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14845 1 Dasinfomedia 1 Wpchurch Church Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14844 1 Dasinfomedia 1 Wpgym Gym Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
CVE-2017-14843 1 Dasinfomedia 1 School Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14842 1 Dasinfomedia 1 Smsmaster Multipurpose Sms Gateway 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
CVE-2017-14807 1 Suse 2 Studio Onsite, Susestudio-ui-server 2026-06-17 5.5 MEDIUM 8.1 HIGH
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL statements, allowing for extraction and modification of data. This issue affects: SUSE Studio onsite susestudio-ui-server version 1.3.17-56.6.3 and prior versions.
CVE-2017-14760 1 Eventespresso 1 Event Espresso Lite 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.
CVE-2017-14758 1 Opentext 1 Document Sciences Xpression 2026-06-17 6.5 MEDIUM 8.8 HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
CVE-2017-14757 1 Opentext 1 Document Sciences Xpression 2026-06-17 6.5 MEDIUM 8.8 HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
CVE-2017-14743 1 Faleemi 2 Fsc-880, Fsc-880 Firmware 2026-06-17 9.3 HIGH 8.1 HIGH
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.
CVE-2017-14738 1 Filerun 1 Filerun 2026-06-17 7.5 HIGH 9.8 CRITICAL
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
CVE-2017-14723 1 Wordpress 1 Wordpress 2026-06-17 7.5 HIGH 9.8 CRITICAL
Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.
CVE-2017-14703 1 Cashbackcomparisonscript 1 Cash Back Comparison 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.
CVE-2017-14652 1 Tapatalk 1 Tapatalk 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote attacker to inject arbitrary SQL commands via an XML-RPC encoded document sent as part of the user registration process.