Vulnerabilities (CVE)

Filtered by CWE-89
Total 14524 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4905 1 Wp-olivecart 2 Olivecart, Olivecartpro 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-16000 1 Eyesofnetwork 1 Eyesofnetwork 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the graph parameter to module/capacity_per_label/index.php.
CVE-2017-15978 1 Arox 1 School Erp Php Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
CVE-2015-2147 1 Phpbugtracker Project 1 Phpbugtracker 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.
CVE-2017-1347 1 Ibm 1 Sterling B2b Integrator 2025-04-20 6.5 MEDIUM 8.8 HIGH
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126462.
CVE-2017-6050 1 Ecava 1 Integraxor 2025-04-20 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.
CVE-2017-17899 1 Dolibarr 1 Dolibarr Erp\/crm 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.
CVE-2017-11419 1 Fiyo 1 Fiyo Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].
CVE-2017-17598 1 Affiliate Mlm Script Project 1 Affiliate Mlm Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
CVE-2017-10839 1 Seopanel 1 Seo Panel 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-8789 1 Accellion 1 File Transfer Appliance 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
CVE-2015-3934 1 Fiyo 1 Fiyo Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.
CVE-2017-17951 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2025-04-20 7.5 HIGH 9.8 CRITICAL
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.
CVE-2017-17597 1 Nearbuy Clone Script Project 1 Nearbuy Clone Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
CVE-2017-15539 1 Zorovavi\/blog Project 1 Zorovavi\/blog 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
CVE-2017-14507 1 Shindiristudio 1 Content Timeline 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.
CVE-2017-17920 1 Rubyonrails 1 Ruby On Rails 2025-04-20 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
CVE-2017-17636 1 Mlm Forced Matrix Project 1 Mlm Forced Matrix 2025-04-20 7.5 HIGH 9.8 CRITICAL
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
CVE-2016-9087 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the fileid parameter.
CVE-2017-17608 1 Kindergarten - Elementary School Listing Script Project 1 Kindergarten - Elementary School Listing Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Child Care Script 1.0 has SQL Injection via the /list city parameter.