Vulnerabilities (CVE)

Filtered by CWE-89
Total 17786 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-6550 1 Kinsey 1 Infor-lawson 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.
CVE-2017-11329 1 Glpi-project 1 Glpi 2025-04-20 7.5 HIGH 9.8 CRITICAL
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
CVE-2016-7788 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2017-15991 1 Vastal 1 Agent Zone 2025-04-20 7.5 HIGH 9.8 CRITICAL
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951, CVE-2009-3497, and CVE-2012-0982.
CVE-2017-14758 1 Opentext 1 Document Sciences Xpression 2025-04-20 6.5 MEDIUM 8.8 HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
CVE-2015-4724 1 Concretecms 1 Concrete Cms 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Concrete5 5.7.3.1.
CVE-2015-2147 1 Phpbugtracker Project 1 Phpbugtracker 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.
CVE-2017-1002014 1 Anblik 1 Image-gallery-with-slideshow 2025-04-20 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
CVE-2017-17607 1 Cms Auditor Website Project 1 Cms Auditor Website 2025-04-20 7.5 HIGH 9.8 CRITICAL
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
CVE-2017-14738 1 Filerun 1 Filerun 2025-04-20 7.5 HIGH 9.8 CRITICAL
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
CVE-2017-17111 1 Scubez 1 Posty Readymade Classifieds 2025-04-20 7.5 HIGH 9.8 CRITICAL
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.
CVE-2016-7803 1 Cybozu 1 Garoon 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.
CVE-2017-14601 1 Pragyan Cms Project 1 Pragyan Cms 2025-04-20 4.0 MEDIUM 4.9 MEDIUM
Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.
CVE-2017-17983 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2025-04-20 6.5 MEDIUM 8.8 HIGH
PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter.
CVE-2017-17950 1 Cells 1 Blog 2025-04-20 6.5 MEDIUM 8.8 HIGH
Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.
CVE-2017-10839 1 Seopanel 1 Seo Panel 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-8930 1 Ibm 1 Kenexa Lms 2025-04-20 6.5 MEDIUM 7.6 HIGH
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2017-15963 1 Itechscripts 1 Gigs Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.
CVE-2017-15081 1 Phpsugar 1 Php Melody 2025-04-20 7.5 HIGH 9.8 CRITICAL
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
CVE-2017-5663 1 Apache 1 Fineract 2025-04-20 6.5 MEDIUM 8.8 HIGH
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.