Vulnerabilities (CVE)

Filtered by CWE-89
Total 20792 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-29622 1 Purchase Order Management Project 1 Purchase Order Management 2026-06-17 N/A 9.8 CRITICAL
Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.
CVE-2023-29598 1 Lmxcms 1 Lmxcms 2026-06-17 N/A 9.8 CRITICAL
lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.
CVE-2023-29597 1 Bloofox 1 Bloofoxcms 2026-06-17 N/A 8.8 HIGH
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.
CVE-2023-29459 1 Redbull 1 Fc Red Bull Salzburg 2026-06-17 N/A 6.1 MEDIUM
The laola.redbull application through 5.1.9-R for Android exposes the exported activity at.redbullsalzburg.android.AppMode.Default.Splash.SplashActivity, which accepts a data: URI. The target of this URI is subsequently loaded into the application's webview, thus allowing the loading of arbitrary content into the context of the application. This can occur via the fcrbs schema or an explicit intent invocation.
CVE-2023-29432 1 Favethemes 1 Houzez 2026-06-17 N/A 8.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3.
CVE-2023-29245 1 Nozominetworks 2 Cmc, Guardian 2026-06-17 N/A 8.1 HIGH
A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted malicious network packets. Malicious users with extensive knowledge on the underlying system may be able to extract arbitrary information from the DBMS in an uncontrolled way, alter its structure and data, and/or affect its availability.
CVE-2023-29154 1 Contec 1 Conprosys Hmi System 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execute an arbitrary SQL command via specially crafted input to the query setting page.
CVE-2023-29119 1 Enelx 2 Waybox Pro, Waybox Pro Firmware 2026-06-17 N/A 9.6 CRITICAL
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.
CVE-2023-29118 1 Enelx 2 Waybox Pro, Waybox Pro Firmware 2026-06-17 N/A 9.6 CRITICAL
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.
CVE-2023-29096 1 Bestwebsoft 1 Contact Form To Db 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.0.
CVE-2023-29095 1 Carrcommunications 1 Rsvpmaker 2026-06-17 N/A 7.6 HIGH
Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions.
CVE-2023-29047 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 N/A 5.3 MEDIUM
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content which is accessible to the imageconverter SQL user account. None No publicly available exploits are known.
CVE-2023-28883 1 Cerebrate-project 1 Cerebrate 2026-06-17 N/A 9.8 CRITICAL
In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.
CVE-2023-28849 1 Glpi-project 1 Glpi 2026-06-17 N/A 10.0 CRITICAL
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.7 contains a patch for this issue. As a workaround, disable native inventory.
CVE-2023-28843 1 202-ecommerce 1 Paypal 2026-06-17 N/A 9.8 CRITICAL
PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain privileges, modify data, and potentially affect system availability. The cause of this issue is that SQL queries were being constructed with user input which had not been properly filtered. Only deployments on PrestaShop 1.6 are affected. Users are advised to upgrade to module version 3.16.4. There are no known workarounds for this vulnerability.
CVE-2023-28839 1 Shoppingfeed 1 Shoppingfeed 2026-06-17 N/A 9.4 CRITICAL
Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2023-28838 1 Glpi-project 1 Glpi 2026-06-17 N/A 9.6 CRITICAL
GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access rights to statistics or reports to extract all data from database and, in some cases, write a webshell on the server. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, remove `Assistance > Statistics` and `Tools > Reports` read rights from every user.
CVE-2023-28788 1 Pagevisitcounter 1 Advanced Page Visit Counter 2026-06-17 N/A 7.1 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 6.4.2.
CVE-2023-28787 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.
CVE-2023-28777 1 Learndash 1 Learndash 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS: from n/a through 4.5.3.