Vulnerabilities (CVE)

Filtered by CWE-89
Total 14524 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1002004 1 Dtracker Project 1 Dtracker 2025-04-20 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
CVE-2017-1000067 1 Modx 1 Revolution 2025-04-20 6.5 MEDIUM 8.8 HIGH
MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.
CVE-2017-16543 1 Zohocorp 1 Manageengine Applications Manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
CVE-2017-15964 1 Nicephpscripts 1 Job Board Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.
CVE-2016-9020 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.
CVE-2017-17824 1 Piwigo 1 Piwigo 2025-04-20 4.0 MEDIUM 4.9 MEDIUM
The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2017-17640 1 Advanced World Database Project 1 Advanced World Database 2025-04-20 7.5 HIGH 9.8 CRITICAL
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
CVE-2015-4669 1 Xceedium 1 Xsuite 2025-04-20 7.2 HIGH 7.8 HIGH
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
CVE-2017-5344 1 Dotcms 1 Dotcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.
CVE-2016-9416 1 Mybb 2 Merge System, Mybb 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-9848 1 Easysitecms 1 Easysite 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute arbitrary SQL commands via an XML document containing a crafted ArticleIDs element within a GetArticleHitsArray element.
CVE-2017-6098 1 Mail-masta Project 1 Mail-masta 2025-04-20 6.5 MEDIUM 7.2 HIGH
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.
CVE-2016-10378 1 E107 1 E107 2025-04-20 6.5 MEDIUM 7.2 HIGH
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
CVE-2015-7569 1 Yeager 1 Yeager Cms 2025-04-20 7.5 HIGH 8.8 HIGH
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.
CVE-2017-17102 1 Fiyo 1 Fiyo Cms 2025-04-20 5.0 MEDIUM 7.5 HIGH
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
CVE-2017-17632 1 Responsive Events And Movie Ticket Booking Script Project 1 Responsive Events And Movie Ticket Booking Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
CVE-2017-1000129 1 S9y 1 Serendipity 2025-04-20 5.0 MEDIUM 7.5 HIGH
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
CVE-2015-3314 1 Tune Library Project 1 Tune Library 2025-04-20 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
CVE-2017-12650 1 Loginizer 1 Loginizer 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
CVE-2017-1000060 1 Eyesofnetwork 1 Eyesofnetwork 2025-04-20 10.0 HIGH 9.8 CRITICAL
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root