Vulnerabilities (CVE)

Filtered by CWE-89
Total 20784 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14844 1 Dasinfomedia 1 Wpgym Gym Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
CVE-2017-14843 1 Dasinfomedia 1 School Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14842 1 Dasinfomedia 1 Smsmaster Multipurpose Sms Gateway 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
CVE-2017-14807 1 Suse 2 Studio Onsite, Susestudio-ui-server 2026-06-17 5.5 MEDIUM 8.1 HIGH
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL statements, allowing for extraction and modification of data. This issue affects: SUSE Studio onsite susestudio-ui-server version 1.3.17-56.6.3 and prior versions.
CVE-2017-14760 1 Eventespresso 1 Event Espresso Lite 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.
CVE-2017-14758 1 Opentext 1 Document Sciences Xpression 2026-06-17 6.5 MEDIUM 8.8 HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
CVE-2017-14757 1 Opentext 1 Document Sciences Xpression 2026-06-17 6.5 MEDIUM 8.8 HIGH
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.
CVE-2017-14743 1 Faleemi 2 Fsc-880, Fsc-880 Firmware 2026-06-17 9.3 HIGH 8.1 HIGH
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.
CVE-2017-14738 1 Filerun 1 Filerun 2026-06-17 7.5 HIGH 9.8 CRITICAL
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
CVE-2017-14723 1 Wordpress 1 Wordpress 2026-06-17 7.5 HIGH 9.8 CRITICAL
Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.
CVE-2017-14703 1 Cashbackcomparisonscript 1 Cash Back Comparison 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.
CVE-2017-14652 1 Tapatalk 1 Tapatalk 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote attacker to inject arbitrary SQL commands via an XML-RPC encoded document sent as part of the user registration process.
CVE-2017-14601 1 Pragyan Cms Project 1 Pragyan Cms 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.
CVE-2017-14600 1 Pragyan Cms Project 1 Pragyan Cms 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
Pragyan CMS v3.0 is vulnerable to an Error-Based SQL injection in cms/admin.lib.php via $_GET['del_black'], resulting in Information Disclosure.
CVE-2017-14512 1 Nexusphp Project 1 Nexusphp 2026-06-17 7.5 HIGH 9.8 CRITICAL
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.
CVE-2017-14508 1 Sugarcrm 1 Sugarcrm 2026-06-17 6.5 MEDIUM 8.8 HIGH
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php. An attacker could exploit these vulnerabilities by sending a crafted SQL request to the affected areas. An exploit could allow the attacker to modify the SQL database. Proper SQL escaping has been added to prevent such exploits.
CVE-2017-14507 1 Shindiristudio 1 Content Timeline 2026-06-17 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.
CVE-2017-14403 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.
CVE-2017-14402 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input validation in include/function.php.
CVE-2017-14401 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT UPDATE" section.