Total
20784 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-21120 | 1 Uqcms | 1 Uqcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num. | |||||
| CVE-2020-21119 | 1 Kliqqi | 1 Kliqqi Cms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code. | |||||
| CVE-2020-21060 | 1 Phpmywind | 1 Phpmywind | 2026-06-17 | N/A | 8.8 HIGH |
| SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page. | |||||
| CVE-2020-21013 | 1 Emlog | 1 Emlog | 2026-06-17 | 6.5 MEDIUM | 7.2 HIGH |
| emlog v6.0.0 contains a SQL injection via /admin/comment.php. | |||||
| CVE-2020-21012 | 1 Hotel And Lodge Booking Management System Project | 1 Hotel And Lodge Booking Management System | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details. | |||||
| CVE-2020-20981 | 1 Metinfo | 1 Metinfo | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information. | |||||
| CVE-2020-20975 | 1 Gxlcms | 1 Gxlcms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter. | |||||
| CVE-2020-20915 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl. | |||||
| CVE-2020-20914 | 1 Publiccms | 1 Publiccms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter. | |||||
| CVE-2020-20913 | 1 Mingsoft | 1 Mcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter. | |||||
| CVE-2020-20800 | 1 Metinfo | 1 Metinfo | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI. | |||||
| CVE-2020-20797 | 1 Flamecms Project | 1 Flamecms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php. | |||||
| CVE-2020-20796 | 1 Flamecms Project | 1 Flamecms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter. | |||||
| CVE-2020-20692 | 1 Gilacms | 1 Gila Cms | 2026-06-17 | 6.5 MEDIUM | 7.2 HIGH |
| GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php. | |||||
| CVE-2020-20675 | 1 Nuishop | 1 Nuishop | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/. | |||||
| CVE-2020-20636 | 1 Joyplus-cms Project | 1 Joyplus-cms | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function. | |||||
| CVE-2020-20625 | 1 Slicedinvoices | 1 Sliced Invoices | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php. | |||||
| CVE-2020-20583 | 1 8cms | 1 Ljcms | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information. | |||||
| CVE-2020-20491 | 1 Opencart | 1 Opencart | 2026-06-17 | N/A | 7.2 HIGH |
| SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php. | |||||
| CVE-2020-20474 | 1 White Shark Systems Project | 1 White Shark Systems | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information. | |||||
