Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45536 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.
CVE-2022-45535 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
CVE-2022-45529 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
CVE-2022-45526 1 Institutional Management Website Project 1 Institutional Management Website 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
CVE-2022-45373 1 Wp-slimstat 1 Slimstat Analytics 2026-06-17 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics allows SQL Injection.This issue affects Slimstat Analytics: from n/a through 5.0.4.
CVE-2022-45355 1 Thimpress 1 Wp Pipes 2026-06-17 N/A 8.2 HIGH
Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions.
CVE-2022-45331 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 7.5 HIGH
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.
CVE-2022-45330 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 7.5 HIGH
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
CVE-2022-45329 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 7.5 HIGH
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.
CVE-2022-45328 1 Church Management System Project 1 Church Management System 2026-06-17 N/A 7.2 HIGH
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php.
CVE-2022-45297 1 Eq Project 1 Eq 2026-06-17 N/A 9.8 CRITICAL
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.
CVE-2022-45278 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 8.8 HIGH
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.
CVE-2022-45165 1 Archibus 1 Web Central 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL injection.
CVE-2022-45135 1 Apache 1 Cocoon 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
CVE-2022-45090 1 Gruparge 1 Smartpower Web 2026-06-17 N/A 8.8 HIGH
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.
CVE-2022-45089 1 Gruparge 1 Smartpower Web 2026-06-17 N/A 8.8 HIGH
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.
CVE-2022-45041 1 Rockoa 1 Xinhu 2026-06-17 N/A 7.5 HIGH
SQL Injection exits in xinhu < 2.5.0
CVE-2022-45030 1 Rconfig 1 Rconfig 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).
CVE-2022-45019 1 Slims 1 Senayan Library Management System 2026-06-17 N/A 7.5 HIGH
SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.
CVE-2022-45010 1 Simple Phone Book\/directory Web App Project 1 Simple Phone Book\/directory Web App 2026-06-17 N/A 9.8 CRITICAL
Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php.