Vulnerabilities (CVE)

Filtered by CWE-89
Total 20793 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30149 2 Ebewe, Prestashop 2 City Autocomplete, Prestashop 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop version 1.5/1.6) or prior to 2.0.3 (for PrestaShop version 1.7), allows remote attackers to execute arbitrary SQL commands via the type, input_name. or q parameter in the autocompletion.php front controller.
CVE-2023-30112 1 Medicine Tracker System Project 1 Medicine Tracker System 2026-06-17 N/A 7.5 HIGH
Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.
CVE-2023-30092 1 Online Pizza Ordering System Project 1 Online Pizza Ordering System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.
CVE-2023-30077 1 Judging Management System Project 1 Judging Management System 2026-06-17 N/A 9.8 CRITICAL
Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.
CVE-2023-30076 1 Judging Management System Project 1 Judging Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=.
CVE-2023-30058 1 Xxyopen 1 Novel-plus 2026-06-17 N/A 9.8 CRITICAL
novel-plus 3.6.2 is vulnerable to SQL Injection.
CVE-2023-30018 1 Judging Management System Project 1 Judging Management System 2026-06-17 N/A 9.8 CRITICAL
Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.
CVE-2023-30016 1 Oretnom23 1 Judging Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.
CVE-2023-30015 1 Oretnom23 1 Judging Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.
CVE-2023-30014 1 Oretnom23 1 Judging Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php.
CVE-2023-2963 1 Olivaekspertiz 1 Oliva Ekspertiz 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oliva Expertise Oliva Expertise EKS allows SQL Injection. This issue affects Oliva Expertise EKS: before 1.2.
CVE-2023-2962 1 Faculty Evaluation System Project 1 Faculty Evaluation System 2026-06-17 5.8 MEDIUM 4.7 MEDIUM
A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affected by this issue is some unknown functionality of the file index.php?page=edit_user. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-230150 is the identifier assigned to this vulnerability.
CVE-2023-2957 1 Lisayazilim 1 Florist Site 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Florist Site allows SQL Injection. This issue affects Florist Site: before 3.0.
CVE-2023-2955 1 Students Online Internship Timesheet System Project 1 Students Online Internship Timesheet System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet System 1.0. Affected is an unknown function of the file rendered_report.php of the component GET Parameter Handler. The manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230142 is the identifier assigned to this vulnerability.
CVE-2023-2951 1 Bus Dispatch And Information System Project 1 Bus Dispatch And Information System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in code-projects Bus Dispatch and Information System 1.0. Affected is an unknown function of the file delete_bus.php. The manipulation of the argument busid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230112.
CVE-2023-2921 1 Kaizencoders 1 Short Url 2026-06-17 N/A 8.8 HIGH
The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.
CVE-2023-2907 1 Marksoft 1 Marksoft 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection. This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.
CVE-2023-2889 1 Veom 1 Service Tracking 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veon Computer Service Tracking Software allows SQL Injection. This issue affects Service Tracking Software: before crm 2.0.
CVE-2023-2865 1 Theme Park Ticketing System Project 1 Theme Park Ticketing System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in SourceCodester Theme Park Ticketing System 1.0. It has been classified as critical. This affects an unknown part of the file print_ticket.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-229821 was assigned to this vulnerability.
CVE-2023-2852 1 Softmedyazilim 1 Selfpatron 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron allows SQL Injection. This issue affects SelfPatron : before 2.0.