Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25928 1 Sitepact 1 Contact Form 7 Extension For Klaviyo 2026-06-17 N/A 7.1 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.
CVE-2024-25927 1 Jmash 1 Postmash 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postMash – custom post order.This issue affects postMash – custom post order: from n/a through 1.2.0.
CVE-2024-25924 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trustindex.Io WP Testimonials.This issue affects WP Testimonials: from n/a through 1.4.3.
CVE-2024-25910 1 Skymoonlabs 1 Moveto 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
CVE-2024-25902 1 Miniorange 1 Malware Scanner 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.
CVE-2024-25897 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 9.8 CRITICAL
ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVE-2024-25896 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 5.3 MEDIUM
ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.
CVE-2024-25894 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 9.8 CRITICAL
ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.
CVE-2024-25893 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 9.1 CRITICAL
ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVE-2024-25892 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 8.1 HIGH
ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.
CVE-2024-25891 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 7.5 HIGH
ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVE-2024-25867 1 Codeastro 1 Membership Management System 2026-06-17 N/A 9.1 CRITICAL
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component.
CVE-2024-25866 1 Codeastro 1 Membership Management System 2026-06-17 N/A 8.8 HIGH
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.
CVE-2024-25849 1 Prestatoolkit 1 Make An Offer\/offer Your Price 2026-06-17 N/A 9.8 CRITICAL
In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .
CVE-2024-25848 1 Team-ever 1 Seo 2026-06-17 N/A 5.9 MEDIUM
In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-25845 1 Cleanpresta 1 Cd Custom Fields 4 Orders 2026-06-17 N/A 9.8 CRITICAL
In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-25843 1 Prestashop 1 Import\/update Bulk Product 2026-06-17 N/A 9.8 CRITICAL
In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.
CVE-2024-25833 1 F-logic 1 Datacube3 2026-06-17 N/A 9.8 CRITICAL
F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database.
CVE-2024-25722 1 Qanything 1 Qanything 2026-06-17 N/A 9.8 CRITICAL
qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.
CVE-2024-25574 1 Deltaww 1 Diaenergie 2026-06-17 N/A 8.8 HIGH
SQL injection vulnerability exists in GetDIAE_usListParameters.