Total
20694 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-19920 | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |||||
| CVE-2026-19919 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |||||
| CVE-2026-19899 | 2026-08-20 | 7.5 HIGH | 7.3 HIGH | ||
| A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |||||
| CVE-2025-10592 | 1 Itsourcecode | 1 Online Public Access Catalog | 2026-08-20 | 6.5 MEDIUM | 6.3 MEDIUM |
| A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/search_text leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. | |||||
| CVE-2017-20277 | 1 Joomboost | 1 Joomla Joomrecipe | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques. | |||||
| CVE-2017-20276 | 1 Simbunch | 1 Simgenealogy | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Attackers can send GET requests to index.php with the option=com_simgenealogy, view=latest parameters and inject malicious SQL in the type parameter to extract sensitive database information. | |||||
| CVE-2017-20278 | 1 Joomboost | 1 Joomrecipe | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL payloads in the category path segment to extract sensitive database information. | |||||
| CVE-2017-20279 | 1 Extensions | 1 Joomla Payage | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to extract sensitive database information using boolean-based blind or time-based blind techniques. | |||||
| CVE-2017-20280 | 1 Myportfolio | 1 Myportfolio | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attackers can send GET requests to index.php with malicious pid values in the task=project&view=grid endpoint to extract sensitive database information. | |||||
| CVE-2017-20281 | 1 Joomlaboat | 1 Extra Search | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the establename field to extract sensitive database information. | |||||
| CVE-2017-20282 | 1 Soft-php | 1 Jcart For Opencart | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the option=com_jcart&route=product/product parameters and malicious product_id values to extract sensitive database information. | |||||
| CVE-2019-25748 | 1 Cmsjunkie | 1 Jhotelreservation | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms parameter to extract sensitive database information including version details. | |||||
| CVE-2019-25749 | 1 Cmsjunkie | 1 J-cruiseportal | 2026-08-19 | N/A | 7.1 HIGH |
| Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to extract sensitive database information or manipulate database records. | |||||
| CVE-2019-25750 | 1 Cmsjunkie | 1 Multiplehotelreservation | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL UNION SELECT statements to extract sensitive database information including table names and column data. | |||||
| CVE-2019-25751 | 1 Cmsjunkie | 1 Classifiedsmanager | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the displayads component to extract sensitive database information including usernames, databases, and version details. | |||||
| CVE-2019-25752 | 1 Cmsjunkie | 1 J-businessdirectory | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the option=com_jbusinessdirectory&task=categories.getCategories parameters and inject UNION-based SQL statements in the type parameter to extract database information including schema names and sensitive data. | |||||
| CVE-2019-25753 | 1 Wdmtech | 1 Vmap | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter. Attackers can send GET requests to index.php with the option=com_vmap&task=loadmarker parameters containing SQL injection payloads to manipulate database queries and extract sensitive information. | |||||
| CVE-2026-19631 | 1 Tenable | 1 Security Center | 2026-08-19 | N/A | 4.9 MEDIUM |
| A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials. | |||||
| CVE-2026-19680 | 1 Tenable | 1 Security Center | 2026-08-19 | N/A | 7.1 HIGH |
| A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. | |||||
| CVE-2017-20263 | 1 Focalpointx | 1 Focalpoint | 2026-08-19 | N/A | 8.2 HIGH |
| Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_focalpoint, view=location, and a crafted id parameter containing SQL commands to extract sensitive database information. | |||||
