Vulnerabilities (CVE)

Filtered by CWE-89
Total 17808 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23492 1 Idehweb 1 Login With Phone Number 2025-04-03 N/A 8.8 HIGH
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.
CVE-2023-23490 1 Ays-pro 1 Survey Maker 2025-04-03 N/A 8.8 HIGH
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.
CVE-2023-23489 1 Sandhillsdev 1 Easy Digital Downloads 2025-04-03 N/A 9.8 CRITICAL
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
CVE-2023-23488 1 Strangerstudios 1 Paid Memberships Pro 2025-04-03 N/A 9.8 CRITICAL
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.
CVE-2022-48152 1 Remoteclinic 1 Remote Clinic 2025-04-03 N/A 9.8 CRITICAL
SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parameter to /medicines/profile.php.
CVE-2022-46887 1 Nexusphp 1 Nexusphp 2025-04-03 N/A 9.8 CRITICAL
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.
CVE-2022-47105 1 Jeecg 1 Jeecg Boot 2025-04-03 N/A 9.8 CRITICAL
Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
CVE-2020-29297 1 Online Food Ordering System Project 1 Online Food Ordering System 2025-04-03 N/A 9.8 CRITICAL
Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.
CVE-2024-55509 1 Codeastro 1 Complaint Management System 2025-04-03 N/A 9.8 CRITICAL
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.
CVE-2024-12890 1 Code-projects 1 Online Exam Mastering System 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /update.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12891 1 Code-projects 1 Online Exam Mastering System 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12926 1 Codezips 1 Project Management System 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in Codezips Project Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/forms/advanced.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2024-12928 1 Code-projects 1 Simple Admin Panel 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. This affects an unknown part. The manipulation of the argument c_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12929 1 Code-projects 1 Student Management System 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in code-projects Student Management System 1.0.00 and classified as critical. This vulnerability affects unknown code of the file /addCatController.php. The manipulation of the argument size leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12931 1 Code-projects 1 Simple Admin Panel 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been classified as critical. Affected is an unknown function of the file /addCatController.php. The manipulation of the argument size leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12934 1 Code-projects 1 Simple Admin Panel 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in code-projects Simple Admin Panel 1.0. This affects an unknown part of the file updateItemController.php. The manipulation of the argument p_desk leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-54842 1 Phpgurukul 1 Online Nurse Hiring System 2025-04-03 N/A 9.8 CRITICAL
A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.
CVE-2024-55099 1 Phpgurukul 1 Online Nurse Hiring System 2025-04-03 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.
CVE-2024-54810 1 Phpgurukul 1 Pre-school Enrollment System 2025-04-03 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.
CVE-2024-54811 1 Phpgurukul 1 Park Ticketing Management System 2025-04-03 N/A 9.8 CRITICAL
A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.