Vulnerabilities (CVE)

Filtered by CWE-89
Total 20791 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24163 1 Hutool 1 Hutool 2026-06-17 N/A 9.8 CRITICAL
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
CVE-2023-24084 1 Chikoi Project 1 Chikoi 2026-06-17 N/A 9.8 CRITICAL
ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.
CVE-2023-24000 1 Gamipress 1 Gamipress 2026-06-17 N/A 8.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through 2.5.7.
CVE-2023-23991 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.
CVE-2023-23948 1 Owncloud 1 Owncloud Client 2026-06-17 N/A 6.2 MEDIUM
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version 3.0, the `filelist` database was deprecated. However, injections affecting `owncloud_database` remain relevant as of version 3.0.
CVE-2023-23824 1 Wp Topbar Project 1 Wp Topbar 2026-06-17 N/A 6.7 MEDIUM
Auth. SQL Injection (SQLi) vulnerability in WP-TopBar <= 5.36 versions.
CVE-2023-23775 1 Fortinet 1 Fortisoar 2026-06-17 N/A 6.5 MEDIUM
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
CVE-2023-23758 1 Creative-solutions 1 Creative Gallery 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CVE-2023-23757 1 Bestaddon 1 Bestaddon Gallery 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CVE-2023-23753 1 Vi-solutions 1 Visforms 2026-06-17 N/A 9.8 CRITICAL
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.
CVE-2023-23737 1 Managewp 1 Broken Link Checker 2026-06-17 N/A 9.3 CRITICAL
Unauth. SQL Injection (SQLi) vulnerability in MainWP MainWP Broken Links Checker Extension plugin <= 4.0 versions.
CVE-2023-23660 1 Mainwp 1 Mainwp Maintenance Extension 2026-06-17 N/A 8.5 HIGH
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <= 4.1.1 versions.
CVE-2023-23651 1 Mainwp 1 Mainwp Google Analytics Extension 2026-06-17 N/A 8.5 HIGH
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.
CVE-2023-23634 1 Documize 1 Documize 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Documize version 5.4.2, allows remote attackers to execute arbitrary code via the user parameter of the /api/dashboard/activity endpoint.
CVE-2023-23574 1 Nozominetworks 2 Cmc, Guardian 2026-06-17 N/A 8.8 HIGH
A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able to extract arbitrary information from the DBMS in an uncontrolled way, alter its structure and data, and/or affect its availability.
CVE-2023-23563 1 Geomatika 1 Isigeo Web 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to obtain sensitive database content via SQL Injection.
CVE-2023-23492 1 Idehweb 1 Login With Phone Number 2026-06-17 N/A 8.8 HIGH
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.
CVE-2023-23490 1 Ays-pro 1 Survey Maker 2026-06-17 N/A 8.8 HIGH
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.
CVE-2023-23489 1 Sandhillsdev 1 Easy Digital Downloads 2026-06-17 N/A 9.8 CRITICAL
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
CVE-2023-23488 1 Strangerstudios 1 Paid Memberships Pro 2026-06-17 N/A 9.8 CRITICAL
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.