Vulnerabilities (CVE)

Filtered by CWE-89
Total 20802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50563 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
CVE-2023-50429 1 Izybat 1 Orange Casiers 2026-06-17 N/A 9.1 CRITICAL
IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection.
CVE-2023-50395 1 Solarwinds 1 Solarwinds Platform 2026-06-17 N/A 8.0 HIGH
SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited
CVE-2023-50360 1 Qnap 1 Video Station 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.1 ( 2024/02/26 ) and later
CVE-2023-50347 1 Hcltech 1 Dryice Myxalytics 2026-06-17 N/A 3.7 LOW
HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. A malicious user can run arbitrary SQL commands including changing system configuration.
CVE-2023-50316 1 Ibm 1 Sterling B2b Integrator 2026-06-17 N/A 6.3 MEDIUM
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2023-50162 1 Phome 1 Empirecms 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
CVE-2023-50073 1 Leadscloud 1 Empirecms 2026-06-17 N/A 9.8 CRITICAL
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
CVE-2023-50071 1 Customer Support System Project 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.
CVE-2023-50070 1 Oretnom23 1 Customer Support System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.
CVE-2023-50061 1 Store-opart 1 Op\'art Easy Redirect 2026-06-17 N/A 9.8 CRITICAL
PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().
CVE-2023-50035 1 Small Crm Project 1 Small Crm 2026-06-17 N/A 9.8 CRITICAL
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
CVE-2023-50030 1 Joommasters 1 Jmssetting 2026-06-17 N/A 9.8 CRITICAL
In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection.
CVE-2023-50028 1 Prestashopmodules 1 Sliding Cart Block 2026-06-17 N/A 9.8 CRITICAL
In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection.
CVE-2023-50027 1 Buy-addons 1 Bazoom Magnifier 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.
CVE-2023-50026 1 Prestamonster 1 Multi Accessories Pro 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts().
CVE-2023-4999 1 Gopiplus 1 Horizontal Scrolling Announcement 2026-06-17 N/A 8.8 HIGH
The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-scrolling] shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2023-4987 1 Infinitietech 1 Taskhub 2026-06-17 5.2 MEDIUM 5.5 MEDIUM
A vulnerability, which was classified as critical, has been found in infinitietech taskhub 2.8.7. Affected by this issue is some unknown functionality of the file /home/get_tasks_list of the component GET Parameter Handler. The manipulation of the argument project/status/user_id/sort/search leads to sql injection. VDB-239798 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-4974 1 Creativeitem 1 Academy Lms 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument price_min/price_max leads to sql injection. The attack may be launched remotely. VDB-239750 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-4928 1 Instantcms 1 Icms2 2026-06-17 N/A 7.2 HIGH
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.