Vulnerabilities (CVE)

Filtered by CWE-89
Total 20803 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-44163 1 Projectworlds 1 Online Movie Ticket Booking System 2026-06-17 N/A 9.8 CRITICAL
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-44091 1 Artica 1 Pandora Fms 2026-06-17 N/A 7.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. This ulnerability allowed SQL injections to be made even if authentication failed.This issue affects Pandora FMS: from 700 through <776.
CVE-2023-44090 1 Artica 1 Pandora Fms 2026-06-17 N/A 6.8 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776.
CVE-2023-44088 1 Pandorafms 1 Pandora Fms 2026-06-17 N/A 5.9 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.
CVE-2023-44047 1 Oretnom23 1 Toll Tax Management System 2026-06-17 N/A 7.2 HIGH
Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.
CVE-2023-44044 1 Superstorefinder 1 Super Store Finder 2026-06-17 N/A 7.2 HIGH
Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /admin/stores.php.
CVE-2023-44025 1 Addify 1 Free Gifts 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component.
CVE-2023-44024 1 Knowband 1 One Page Checkout\, Social Login \& Mailchimp 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component.
CVE-2023-43986 1 Dmconcept 1 Configurator 2026-06-17 N/A 9.8 CRITICAL
DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken.
CVE-2023-43985 1 Sunnytoo 1 Stblogsearch 2026-06-17 N/A 9.8 CRITICAL
SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component.
CVE-2023-43983 1 Presto-changeo 1 Attribute Grid 2026-06-17 N/A 9.8 CRITICAL
Presto Changeo attributegrid up to 2.0.3 was discovered to contain a SQL injection vulnerability via the component disable_json.php.
CVE-2023-43980 1 Presto-changeo 1 Testsitecreator 2026-06-17 N/A 9.8 CRITICAL
Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.
CVE-2023-43979 1 Prestahero 1 Ybc Blog 2026-06-17 N/A 9.8 CRITICAL
ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts().
CVE-2023-43909 1 Hospital Management System Project 1 Hospital Management System 2026-06-17 N/A 9.1 CRITICAL
Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
CVE-2023-43899 1 Hansuncms Project 1 Hansuncms 2026-06-17 N/A 9.8 CRITICAL
hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.
CVE-2023-43836 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 6.5 MEDIUM
There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
CVE-2023-43813 1 Glpi-project 1 Glpi 2026-06-17 N/A 6.5 MEDIUM
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the saved search feature can be used to perform a SQL injection. Version 10.0.11 contains a patch for the issue.
CVE-2023-43794 1 Nocodb 1 Nocodb 2026-06-17 N/A 6.5 MEDIUM
Nocodb is an open source Airtable alternative. Affected versions of nocodb contain a SQL injection vulnerability, that allows an authenticated attacker with creator access to query the underlying database. By supplying a specially crafted payload to the given an attacker can inject arbitrary SQL queries to be executed. Since this is a blind SQL injection, an attacker may need to use time-based payloads which would include a function to delay execution for a given number of seconds. The response time indicates, whether the result of the query execution was true or false. Depending on the result, the HTTP response will be returned after a given number of seconds, indicating TRUE, or immediately, indicating FALSE. In that way, an attacker can reveal the data present in the database. This vulnerability has been addressed in version 0.111.0. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as `GHSL-2023-141`.
CVE-2023-43743 1 Zultys 12 Mx-e, Mx-e Firmware, Mx-se and 9 more 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in the Zultys MX web interface.
CVE-2023-43739 1 Online Book Store Project Project 1 Online Book Store Project 2026-06-17 N/A 9.8 CRITICAL
The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.