Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47859 1 Lead Management System Project 1 Lead Management System 2026-06-17 N/A 9.8 CRITICAL
Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
CVE-2022-47790 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=display&id=.
CVE-2022-47780 1 Bangresto Project 1 Bangresto 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Bangresto 1.0 via the itemID parameter.
CVE-2022-47745 1 Easycorp 1 Zentao 2026-06-17 N/A 8.8 HIGH
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
CVE-2022-47740 1 Seltmann-webdesign 1 Content Management System 2026-06-17 N/A 9.8 CRITICAL
Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.
CVE-2022-47614 1 Inspireui 1 Mstore Api 2026-06-17 N/A 7.5 HIGH
Unauth. SQL Injection (SQLi) vulnerability in InspireUI MStore API plugin <= 3.9.7 versions.
CVE-2022-47605 1 Kunalnagar 1 Custom 404 Pro 2026-06-17 N/A 6.4 MEDIUM
Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions.
CVE-2022-47593 1 Rapidload 1 Rapidload Power-up For Autoptimize 2026-06-17 N/A 8.5 HIGH
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 versions.
CVE-2022-47588 1 Tipsandtricks-hq 1 Simple Photo Gallery 2026-06-17 N/A 6.7 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Peter Petreski Simple Photo Gallery simple-photo-gallery allows SQL Injection.This issue affects Simple Photo Gallery: from n/a through v1.8.1.
CVE-2022-47586 1 Themefic 1 Ultimate Addons For Contact Form 7 2026-06-17 N/A 8.2 HIGH
Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.
CVE-2022-47532 1 Filerun 1 Filerun 2026-06-17 N/A 9.8 CRITICAL
FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.
CVE-2022-47523 1 Zohocorp 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro 2026-06-17 N/A 9.8 CRITICAL
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
CVE-2022-47445 1 Web-x 1 Be-popia-compliant 2026-06-17 N/A 8.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Web-X Be POPIA Compliant be-popia-compliant allows SQL Injection.This issue affects Be POPIA Compliant: from n/a through 1.2.0.
CVE-2022-47432 1 Kemalyazici 1 Shortcode Imdb 2026-06-17 N/A 6.7 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kemal YAZICI - PluginPress Shortcode IMDB allows SQL Injection.This issue affects Shortcode IMDB: from n/a through 6.0.8.
CVE-2022-47430 1 Weblizar 1 School Management - Education \& Learning Management 2026-06-17 N/A 6.7 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar The School Management – Education & Learning Management allows SQL Injection.This issue affects The School Management – Education & Learning Management: from n/a through 4.1.
CVE-2022-47428 1 Wpdevart 1 Booking Calendar 2026-06-17 N/A 6.7 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.
CVE-2022-47426 1 Neshan 1 Neshan Maps 2026-06-17 N/A 6.0 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Neshan Maps Platform Neshan Maps neshan-maps allows SQL Injection.This issue affects Neshan Maps: from n/a through 1.1.4.
CVE-2022-47420 1 Adaplugin 1 Accessibility Suite By Online Ada 2026-06-17 N/A 6.4 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.
CVE-2022-47151 1 Joomsky 1 Js Help Desk 2026-06-17 N/A 8.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.
CVE-2022-47105 1 Jeecg 1 Jeecg Boot 2026-06-17 N/A 9.8 CRITICAL
Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.