Vulnerabilities (CVE)

Filtered by CWE-89
Total 17786 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-9333 1 Moxa 1 Softcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTION).
CVE-2017-9603 1 Intensewp 1 Wp Jobs 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.
CVE-2017-17916 1 Rubyonrails 1 Rails 2025-04-20 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
CVE-2017-15373 1 Softwarepublico 1 E-sic 2025-04-20 7.5 HIGH 9.8 CRITICAL
E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area).
CVE-2017-6088 1 Eyesofnetwork 1 Eyesofnetwork 2025-04-20 9.0 HIGH 7.2 HIGH
Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.
CVE-2017-17625 1 On Demand Marketplace Script Project 1 On Demand Marketplace Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
CVE-2017-15979 1 Odallated 1 Shareet 2025-04-20 7.5 HIGH 9.8 CRITICAL
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
CVE-2017-16848 1 Zohocorp 1 Manageengine Applications Manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
CVE-2017-6050 1 Ecava 1 Integraxor 2025-04-20 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.
CVE-2017-14508 1 Sugarcrm 1 Sugarcrm 2025-04-20 6.5 MEDIUM 8.8 HIGH
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php. An attacker could exploit these vulnerabilities by sending a crafted SQL request to the affected areas. An exploit could allow the attacker to modify the SQL database. Proper SQL escaping has been added to prevent such exploits.
CVE-2017-17630 1 Yoga Class Script Project 1 Yoga Class Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-3899 1 Mcafee 1 Advanced Threat Defense 2025-04-20 4.0 MEDIUM 6.5 MEDIUM
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
CVE-2017-1000120 1 Frappe 1 Frappe 2025-04-20 6.5 MEDIUM 8.8 HIGH
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.
CVE-2017-6571 1 Mail-masta Project 1 Mail-masta 2025-04-20 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.
CVE-2017-1002028 1 Angrybyte 1 Gallery-transformation 2025-04-20 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.
CVE-2017-15988 1 Nicephpscripts 1 Nice Php Faq Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.
CVE-2017-10899 1 Ark-web 1 A-reserve 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-17822 1 Piwigo 1 Piwigo 2025-04-20 4.0 MEDIUM 4.9 MEDIUM
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2014-2023 1 Tapatalk 1 Tapatalk 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in mobiquo/functions/.
CVE-2017-17823 1 Piwigo 1 Piwigo 2025-04-20 4.0 MEDIUM 4.9 MEDIUM
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.