Vulnerabilities (CVE)

Filtered by CWE-89
Total 19894 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1002026 1 Eventespresso 1 Event Espresso 2026-06-17 6.5 MEDIUM 8.8 HIGH
Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.
CVE-2017-1002025 1 Add-edit-delete-listing-for-member-module Project 1 Add-edit-delete-listing-for-member-module 2026-06-17 6.5 MEDIUM 7.2 HIGH
Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement.
CVE-2017-1002023 1 Daisythemes 1 Easy Team Manager 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin Easy Team Manager v1.3.2, The code does not sanitize id before making it part of an SQL statement in file ./easy-team-manager/inc/easy_team_manager_desc_edit.php
CVE-2017-1002022 1 Surveys Project 1 Surveys 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query.
CVE-2017-1002021 1 Surveys Project 1 Surveys 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.
CVE-2017-1002020 1 Surveys Project 1 Surveys 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.
CVE-2017-1002019 1 Eventr Project 1 Eventr 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this allows for blind SQL injection via the event parameter.
CVE-2017-1002018 1 Eventr Project 1 Eventr 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this allows for blind SQL injection via the event parameter.
CVE-2017-1002015 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.
CVE-2017-1002014 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
CVE-2017-1002013 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.
CVE-2017-1002012 1 Anblik 1 Image-gallery-with-slideshow 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.
CVE-2017-1002010 1 Ontraport 1 Membership Simplified 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function.
CVE-2017-1002009 1 Ontraport 1 Membership Simplified 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.
CVE-2017-1002005 1 Dtracker Project 1 Dtracker 2026-06-17 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.
CVE-2017-1002004 1 Dtracker Project 1 Dtracker 2026-06-17 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
CVE-2017-1000474 1 Vehicle Sales Management System Project 1 Vehicle Sales Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability, which leads to remote code executing.
CVE-2017-1000444 1 Openhacker Project 1 Openhacker 2026-06-17 7.5 HIGH 9.8 CRITICAL
Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure and remote code execution
CVE-2017-1000129 1 S9y 1 Serendipity 2026-06-17 5.0 MEDIUM 7.5 HIGH
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
CVE-2017-1000120 1 Frappe 1 Frappe 2026-06-17 6.5 MEDIUM 8.8 HIGH
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.