Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13572 1 Adenion 1 Blog2social 2019-08-13 7.5 HIGH 9.8 CRITICAL
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
CVE-2019-14313 1 10web 1 Photo Gallery 2019-08-13 10.0 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
CVE-2019-14529 1 Open-emr 1 Openemr 2019-08-13 7.5 HIGH 9.8 CRITICAL
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
CVE-2019-14695 1 Sygnoos 1 Popup Builder 2019-08-13 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.
CVE-2019-12279 1 Nagios 1 Nagios Xi 2019-08-09 7.5 HIGH 9.8 CRITICAL
** DISPUTED ** Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any valid injection that can be done with the variable provided, and while the username value being passed does get used in a SQL query, it is passed through SQL escaping functions when creating the call. The vendor tried re-creating the issue with no luck.
CVE-2019-14348 1 Beardev 1 Joomsport 2019-08-09 7.5 HIGH 9.8 CRITICAL
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
CVE-2019-13026 1 Oxid-esales 1 Eshop 2019-08-07 7.5 HIGH 9.8 CRITICAL
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.
CVE-2019-13571 1 Vsourz 1 Advanced Cf7 Db 2019-08-06 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
CVE-2019-7139 1 Magento 1 Magento 2019-08-06 7.5 HIGH 9.8 CRITICAL
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CVE-2016-10817 1 Cpanel 1 Cpanel 2019-08-06 10.0 HIGH 9.8 CRITICAL
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
CVE-2019-10866 1 10web 1 Form Maker 2019-08-03 7.5 HIGH 9.8 CRITICAL
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
CVE-2018-20887 1 Cpanel 1 Cpanel 2019-08-01 7.5 HIGH 9.8 CRITICAL
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
CVE-2019-13413 1 Boiteasite 1 Rencontre 2019-07-31 7.5 HIGH 9.8 CRITICAL
The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.
CVE-2019-13573 1 Foliovision 1 Fv Flowplayer Video Player 2019-07-31 10.0 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
CVE-2019-13569 1 Icegram 1 Email Subscribers \& Newsletters 2019-07-31 10.0 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
CVE-2018-19281 1 Centreon 1 Centreon 2019-07-30 7.5 HIGH 9.8 CRITICAL
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
CVE-2019-1010191 1 Marginalia Project 1 Marginalia 2019-07-29 7.5 HIGH 9.8 CRITICAL
marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is: Hacker inputs a SQL to a vulnerable vector(header, http parameter, etc). The fixed version is: 1.6.
CVE-2019-12193 1 H3c 1 H3cloud Os 2019-07-29 7.5 HIGH 9.8 CRITICAL
H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter.
CVE-2019-1010153 1 Zzcms 1 Zzcms 2019-07-24 7.5 HIGH 9.8 CRITICAL
zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.
CVE-2019-1010148 1 Zzcms 1 Zzcms 2019-07-24 7.5 HIGH 9.8 CRITICAL
zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.
CVE-2019-1010248 1 I-doit 1 I-doit 2019-07-23 7.5 HIGH 9.8 CRITICAL
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.
CVE-2019-14231 1 Onionbuzz 1 Onionbuzz 2019-07-23 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.
CVE-2019-14230 1 Onionbuzz 1 Onionbuzz 2019-07-23 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.
CVE-2019-1010104 1 Techytalk 1 Quick Chat 2019-07-23 7.5 HIGH 9.8 CRITICAL
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.
CVE-2019-13575 1 Wpeverest 1 Everest Forms 2019-07-19 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php
CVE-2019-13447 1 Sertek 1 Xpare 2019-07-18 10.0 HIGH 9.8 CRITICAL
An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could access the backend database via SQL injection.
CVE-2019-13027 1 Realization 1 Concerto Critical Chain Planner 2019-07-15 7.5 HIGH 9.8 CRITICAL
Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.
CVE-2019-13489 1 Trape Project 1 Trape 2019-07-14 7.5 HIGH 9.8 CRITICAL
Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.
CVE-2019-13507 1 Hidea 1 Az Admin 2019-07-14 7.5 HIGH 9.8 CRITICAL
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.
CVE-2019-12723 1 Teclib-edition 1 Fields 2019-07-11 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.
CVE-2019-10653 1 Hsycms 1 Hsycms 2019-07-11 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page.
CVE-2019-11512 1 Contao 1 Contao 2019-07-10 7.5 HIGH 9.8 CRITICAL
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
CVE-2019-13275 1 Veronalabs 1 Wp Statistics 2019-07-10 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
CVE-2019-12850 1 Jetbrains 1 Youtrack 2019-07-10 7.5 HIGH 9.8 CRITICAL
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.
CVE-2019-13292 1 Weberp 1 Weberp 2019-07-10 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.
CVE-2019-13375 2 Dlink, Microsoft 2 Central Wifimanager, Windows 2019-07-09 7.5 HIGH 9.8 CRITICAL
A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication.
CVE-2019-13373 2 Dlink, Microsoft 2 Central Wifimanager, Windows 2019-07-09 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL.
CVE-2017-18346 1 Web-gooroo 1 Cms Web-gooroo 2019-07-05 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.
CVE-2019-13086 1 Cszcms 1 Csz Cms 2019-07-03 7.5 HIGH 9.8 CRITICAL
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
CVE-2017-17871 1 Jextn 1 Jextn Question And Answer 2019-07-01 7.5 HIGH 9.8 CRITICAL
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
CVE-2019-9086 1 Digitaldruid 1 Hoteldruid 2019-07-01 7.5 HIGH 9.8 CRITICAL
HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
CVE-2019-9087 1 Digitaldruid 1 Hoteldruid 2019-07-01 7.5 HIGH 9.8 CRITICAL
HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
CVE-2019-12939 1 Livezilla 1 Livezilla 2019-06-26 7.5 HIGH 9.8 CRITICAL
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.
CVE-2019-12960 1 Livezilla 1 Livezilla 2019-06-25 7.5 HIGH 9.8 CRITICAL
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.
CVE-2018-15868 1 Chronoscan 1 Chronoscan 2019-06-24 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbitrary SQL commands via the wcr_machineid cookie.
CVE-2018-17386 1 Thephpfactory 1 Micro Deal Factory 2019-06-21 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
CVE-2018-17388 1 Ranksol 1 Twilio Web To Fax Machine System 2019-06-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.
CVE-2018-17374 1 Thephpfactory 1 Auction Factory 2019-06-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-17381 1 Thephpfactory 1 Dutch Auction Factory 2019-06-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-18758 1 Open Faculty Evaluation System Project 1 Open Faculty Evaluation System 2019-06-20 7.5 HIGH 9.8 CRITICAL
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.