Total
15167 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-25403 | 2025-05-06 | N/A | 9.8 CRITICAL | ||
Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php. | |||||
CVE-2022-40839 | 1 Ndk-design | 1 Ndkadvancedcustomizationfields | 2025-05-06 | N/A | 7.5 HIGH |
A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data. | |||||
CVE-2022-3254 | 1 Strategy11 | 1 Awp Classifieds | 2025-05-06 | N/A | 9.8 CRITICAL |
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection | |||||
CVE-2024-2018 | 1 Melapress | 1 Wp Activity Log | 2025-05-06 | N/A | 8.8 HIGH |
The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. One demonstrated attack included the injection of a PHP Object. | |||||
CVE-2024-13344 | 1 Smartcmsmarket | 1 Advance Seat Reservation Management For Woocommerce | 2025-05-06 | N/A | 7.5 HIGH |
The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'profileId' parameter in all versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
CVE-2024-13322 | 1 Scripteo | 1 Ads Pro | 2025-05-06 | N/A | 7.5 HIGH |
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
CVE-2024-42765 | 1 Kjayvik | 1 Bus Ticket Reservation System | 2025-05-06 | N/A | 9.8 CRITICAL |
A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters. | |||||
CVE-2022-43352 | 1 Sanitization Management System Project | 1 Sanitization Management System | 2025-05-05 | N/A | 7.2 HIGH |
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote. | |||||
CVE-2022-43350 | 1 Sanitization Management System Project | 1 Sanitization Management System | 2025-05-05 | N/A | 7.2 HIGH |
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_inquiry. | |||||
CVE-2022-43052 | 1 Online Diagnostic Lab Management System Project | 1 Online Diagnostic Lab Management System | 2025-05-05 | N/A | 7.2 HIGH |
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete. | |||||
CVE-2022-43051 | 1 Online Diagnostic Lab Management System Project | 1 Online Diagnostic Lab Management System | 2025-05-05 | N/A | 7.2 HIGH |
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test. | |||||
CVE-2022-43049 | 1 Canteen Management System Project | 1 Canteen Management System | 2025-05-05 | N/A | 7.2 HIGH |
Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youthappam/add-food.php. | |||||
CVE-2022-42990 | 1 Oretnom23 | 1 Food Ordering Management System | 2025-05-05 | N/A | 7.2 HIGH |
Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all-orders.php?status=Cancelled%20by%20Customer. | |||||
CVE-2022-27431 | 1 Wuzhicms | 1 Wuzhicms | 2025-05-05 | 7.5 HIGH | 9.8 CRITICAL |
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php. | |||||
CVE-2018-11528 | 1 Wuzhicms | 1 Wuzhicms | 2025-05-05 | 7.5 HIGH | 9.8 CRITICAL |
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI. | |||||
CVE-2020-20122 | 1 Wuzhicms | 1 Wuzhicms | 2025-05-05 | 7.5 HIGH | 9.8 CRITICAL |
Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php. | |||||
CVE-2024-25288 | 1 Slims | 1 Senayan Library Management System | 2025-05-05 | N/A | 4.9 MEDIUM |
SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php. | |||||
CVE-2022-21720 | 1 Glpi-project | 1 Glpi | 2025-05-05 | 4.0 MEDIUM | 4.9 MEDIUM |
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability. | |||||
CVE-2022-1505 | 1 Carrcommunications | 1 Rsvpmaker | 2025-05-05 | 5.0 MEDIUM | 9.8 CRITICAL |
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6. | |||||
CVE-2022-1453 | 1 Carrcommunications | 1 Rsvpmaker | 2025-05-05 | 5.0 MEDIUM | 9.8 CRITICAL |
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5. |