Vulnerabilities (CVE)

Filtered by CWE-89
Total 15257 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-3694 1 Modified 1 Ecommerce Shopsoftware 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/easybillcsv.php.
CVE-2017-6050 1 Ecava 1 Integraxor 2025-04-20 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.
CVE-2017-1000120 1 Frappe 1 Frappe 2025-04-20 6.5 MEDIUM 8.8 HIGH
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.
CVE-2017-17573 1 Fortunescripts 1 Ebay Clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.
CVE-2017-11418 1 Fiyo 1 Fiyo Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].
CVE-2017-9427 1 Bigtreecms 1 Bigtree Cms 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form-create.php. The attacker creates a crafted table name at admin/developer/modules/designer/ and the injection is visible at admin/dashboard/vitals-statistics/integrity/check/?external=true.
CVE-2017-17614 1 Hotel Restaurant Reviews And Feedback Script Project 1 Hotel Restaurant Reviews And Feedback Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Food Order Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-4974 2 Cloudfoundry, Pivotal Software 3 Cf-release, Cloud Foundry Uaa Bosh, Cloud Foundry Uaa 2025-04-20 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior to v24.8, and other versions prior to v30.1. An authorized user can use a blind SQL injection attack to query the contents of the UAA database, aka "Blind SQL Injection with privileged UAA endpoints."
CVE-2017-17822 1 Piwigo 1 Piwigo 2025-04-20 4.0 MEDIUM 4.9 MEDIUM
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2016-8930 1 Ibm 1 Kenexa Lms 2025-04-20 6.5 MEDIUM 7.6 HIGH
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2017-17900 1 Dolibarr 1 Dolibarr Erp\/crm 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.
CVE-2016-1914 1 Blackberry 1 Blackberry Enterprise Service 2025-04-20 6.8 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.
CVE-2017-12276 1 Cisco 1 Prime Collaboration Provisioning 2025-04-20 5.5 MEDIUM 8.1 HIGH
A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. The attacker could read or write information from the SQL database. The vulnerability is due to a lack of proper validation on user-supplied input within SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application. An exploit could allow the attacker to determine the presence of certain values and write malicious input in the SQL database. The attacker would need to have valid user credentials. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.3. Cisco Bug IDs: CSCvf47935.
CVE-2015-4669 1 Xceedium 1 Xsuite 2025-04-20 7.2 HIGH 7.8 HIGH
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
CVE-2017-1002018 1 Eventr Project 1 Eventr 2025-04-20 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this allows for blind SQL injection via the event parameter.
CVE-2015-3934 1 Fiyo 1 Fiyo Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.
CVE-2017-17957 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2025-04-20 7.5 HIGH 9.8 CRITICAL
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.
CVE-2017-15973 1 Sokial 1 Sokial 2025-04-20 7.5 HIGH 9.8 CRITICAL
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.
CVE-2017-14345 1 Blog Project 1 Blog 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php.
CVE-2017-6576 1 Mail-masta Project 1 Mail-masta 2025-04-20 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter: id.