Vulnerabilities (CVE)

Filtered by CWE-89
Total 20784 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-17900 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.
CVE-2017-17899 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.
CVE-2017-17897 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2017-17895 1 Basic Job Site Script Project 1 Basic Job Site Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.
CVE-2017-17892 1 Readymade Video Sharing Script Project 1 Readymade Video Sharing Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search parameter.
CVE-2017-17875 1 Jextn 1 Jextn Faq Pro 2026-06-17 7.5 HIGH 9.8 CRITICAL
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17873 1 Vanguard Project 1 Marketplace Digital Products Php 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
CVE-2017-17872 1 Jextn 1 Jextn Video Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17871 1 Jextn 1 Jextn Question And Answer 2026-06-17 7.5 HIGH 9.8 CRITICAL
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
CVE-2017-17870 1 Jbuildozer 1 Jbuildozer 2026-06-17 7.5 HIGH 9.8 CRITICAL
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
CVE-2017-17829 1 Doditsolutions 1 Bus Booking Script 2026-06-17 6.5 MEDIUM 7.2 HIGH
Bus Booking Script has SQL Injection via the admin/view_seatseller.php sp_id parameter or the admin/view_member.php memid parameter.
CVE-2017-17824 1 Piwigo 1 Piwigo 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2017-17823 1 Piwigo 1 Piwigo 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2017-17822 1 Piwigo 1 Piwigo 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2017-17779 1 Paid To Read Script Project 1 Paid To Read Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.
CVE-2017-17731 1 Dedecms 1 Dedecms 2026-06-17 7.5 HIGH 9.8 CRITICAL
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
CVE-2017-17730 1 Dedecms 1 Dedecms 2026-06-17 7.5 HIGH 9.8 CRITICAL
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
CVE-2017-17721 1 Zuuse 1 Beims Contractorweb .net 2026-06-17 7.5 HIGH 9.8 CRITICAL
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.
CVE-2017-17713 1 Boxug 1 Trape 2026-06-17 7.5 HIGH 9.8 CRITICAL
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /register lat parameter, the /register lon parameter, the /register org parameter, the /register query parameter, the /register region parameter, the /register regionName parameter, the /register timezone parameter, the /register vId parameter, the /register zip parameter, or the /tping id parameter.
CVE-2017-17695 1 Techno - Portfolio Management Panel Project 1 Techno - Portfolio Management Panel 2026-06-17 6.5 MEDIUM 8.8 HIGH
Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter.