Vulnerabilities (CVE)

Filtered by CWE-89
Total 20793 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33479 1 Remoteclinic 1 Remote Clinic 2026-06-17 N/A 9.8 CRITICAL
RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
CVE-2023-33478 1 Remoteclinic 1 Remote Clinic 2026-06-17 N/A 9.8 CRITICAL
RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
CVE-2023-33439 1 Faculty Evaluation System Project 1 Faculty Evaluation System 2026-06-17 N/A 7.2 HIGH
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.
CVE-2023-33367 1 Assaabloy 1 Control Id Idsecure 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.
CVE-2023-33366 1 Supremainc 1 Biostar 2 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitrary SQL commands.
CVE-2023-33362 1 Piwigo 1 Piwigo 2026-06-17 N/A 9.8 CRITICAL
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
CVE-2023-33361 1 Piwigo 1 Piwigo 2026-06-17 N/A 9.8 CRITICAL
Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.
CVE-2023-33338 1 Phpgurukul 1 Old Age Home Management System 2026-06-17 N/A 9.8 CRITICAL
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
CVE-2023-33331 1 Woo 1 Product Vendors 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.
CVE-2023-33330 1 Woocommerce 1 Automatewoo 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.50.
CVE-2023-33280 1 Storecommander 1 Quickaccounting 2026-06-17 N/A 9.8 CRITICAL
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
CVE-2023-33279 1 Scfixmyprestashop Project 1 Scfixmyprestashop 2026-06-17 N/A 9.8 CRITICAL
In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
CVE-2023-33278 1 Storecommander 1 Customers Export 2026-06-17 N/A 9.8 CRITICAL
In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
CVE-2023-33209 1 Crawlspider 1 Seo Change Monitor 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrawlSpider SEO Change Monitor – Track Website Changes.This issue affects SEO Change Monitor – Track Website Changes: from n/a through 1.2.
CVE-2023-33180 1 Xibosignage 1 Xibo 2026-06-17 N/A 6.5 MEDIUM
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the `/display/map` API route inside the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values in to the `bounds` parameter. Users should upgrade to version 3.3.5, which fixes this issue. There are no known workarounds aside from upgrading.
CVE-2023-33179 1 Xibosignage 1 Xibo 2026-06-17 N/A 6.5 MEDIUM
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.5 in the `nameFilter` function used throughout the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values for logical operators. Users should upgrade to version 3.3.5 which fixes this issue. There are no known workarounds aside from upgrading.
CVE-2023-33178 1 Xibosignage 1 Xibo 2026-06-17 N/A 6.5 MEDIUM
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `/dataset/data/{id}` API route inside the CMS starting in version 1.4.0 and prior to versions 2.3.17 and 3.3.5. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values in to the `filter` parameter. Values allowed in the filter parameter are checked against a deny list of commands that should not be allowed, however this checking was done in a case sensitive manor and so it is possible to bypass these checks by using unusual case combinations. Users should upgrade to version 2.3.17 or 3.3.5, which fix this issue. There are no workarounds aside from upgrading.
CVE-2023-32754 1 Thinkingsoftware 1 Efence 2026-06-17 N/A 9.8 CRITICAL
Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
CVE-2023-32743 1 Woocommerce 1 Automatewoo 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 5.7.1.
CVE-2023-32741 1 Itpathsolutions 1 Contact Form To Any Api 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.