Vulnerabilities (CVE)

Filtered by CWE-89
Total 15238 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-5598 1 Eclinicalworks 1 Patient Portal 2025-04-20 5.0 MEDIUM 7.5 HIGH
An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects the EmployeePortalServlet page and the following parameter: employer.
CVE-2017-15974 1 Datacomponents 1 Tpanel 2025-04-20 7.5 HIGH 9.8 CRITICAL
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
CVE-2017-5345 1 Metalgenix 1 Genixcms 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.
CVE-2017-1183 1 Ibm 1 Tivoli Monitoring 2025-04-20 5.4 MEDIUM 7.5 HIGH
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.
CVE-2017-7581 1 News System Project 1 News System 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
CVE-2017-9603 1 Intensewp 1 Wp Jobs 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.
CVE-2017-6089 1 Phpcollab 1 Phpcollab 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to calendar/deletecalendar.php.
CVE-2016-7783 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
CVE-2017-10682 1 Piwigo 1 Piwigo 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
CVE-2017-15381 1 Softwarepublico 1 E-sic 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
CVE-2017-15961 1 Iproject Management System Project 1 Iproject Management System 2025-04-20 7.5 HIGH 9.8 CRITICAL
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
CVE-2017-17731 1 Dedecms 1 Dedecms 2025-04-20 7.5 HIGH 9.8 CRITICAL
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
CVE-2017-17906 1 Car Rental Script Project 1 Car Rental Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.
CVE-2017-9848 1 Easysitecms 1 Easysite 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute arbitrary SQL commands via an XML document containing a crafted ArticleIDs element within a GetArticleHitsArray element.
CVE-2017-9418 1 Goldplugins 1 Testimonials Plugin Easy Testimonials 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php.
CVE-2017-17950 1 Cells 1 Blog 2025-04-20 6.5 MEDIUM 8.8 HIGH
Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.
CVE-2017-15880 1 Eyesofnetwork 1 Eyesofnetwork 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the group_name parameter to module/admin_group/add_modify_group.php (for insert_group and update_group).
CVE-2016-9019 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.
CVE-2017-11582 1 Finecms 1 Finecms 2025-04-20 7.5 HIGH 9.8 CRITICAL
dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Template.php.
CVE-2015-7568 1 Yeager 1 Yeager Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.