Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24391 1 Cashtomer Project 1 Cashtomer 2021-09-09 6.5 MEDIUM 8.8 HIGH
An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24392 1 Swiftcrm 1 Club-management-software 2021-09-09 6.5 MEDIUM 7.2 HIGH
An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24394 1 Easy Testimonial Manager Project 1 Easy Testimonial Manager 2021-09-09 6.5 MEDIUM 7.2 HIGH
An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection
CVE-2021-24393 1 Comment Highlighter Project 1 Comment Highlighter 2021-09-09 6.5 MEDIUM 7.2 HIGH
A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24395 1 Geekwebsolution 1 Embed Youtube Video 2021-09-09 6.5 MEDIUM 7.2 HIGH
The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2015-8157 1 Broadcom 5 Symantec Critical System Protection, Symantec Data Center Security Server, Symantec Data Center Security Server And Agents and 2 more 2021-09-09 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-5151 1 Panasonic 1 Video Insight Web Client 2021-09-09 7.5 HIGH 7.3 HIGH
An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions. A SQL Injection vulnerability has been identified, which may allow remote code execution.
CVE-2021-24580 1 Wow-estore 1 Side Menu 2021-09-02 6.5 MEDIUM 8.8 HIGH
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue
CVE-2020-18913 1 Ecisp 1 Espcms-p8 2021-09-01 5.0 MEDIUM 7.5 HIGH
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information.
CVE-2020-19821 1 Wdoyo 1 Doyocms 2021-09-01 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
CVE-2020-18116 1 Youdiancms 1 Youdiancms 2021-09-01 6.5 MEDIUM 8.8 HIGH
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
CVE-2021-3264 1 Cxuu 1 Cxuucms 2021-09-01 6.5 MEDIUM 7.2 HIGH
SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php.
CVE-2021-39376 1 Philips 1 Tasy Electronic Medical Record 2021-08-31 6.5 MEDIUM 8.8 HIGH
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.
CVE-2021-24557 1 Nimble3 1 M-vslider 2021-08-30 6.5 MEDIUM 7.2 HIGH
The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role.
CVE-2021-24497 1 Satollo 1 Giveaway 2021-08-30 6.5 MEDIUM 7.2 HIGH
The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.
CVE-2021-36748 1 Prestahome 1 Blog 2021-08-30 5.0 MEDIUM 7.5 HIGH
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.
CVE-2020-18477 1 Hucart 1 Hucart 2021-08-27 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
CVE-2020-18476 1 Hucart 1 Hucart 2021-08-27 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
CVE-2021-24550 1 Broken Link Manager Project 1 Broken Link Manager 2021-08-26 6.5 MEDIUM 7.2 HIGH
The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issue
CVE-2021-24552 1 Simple Events Calendar Project 1 Simple Events Calendar 2021-08-26 6.5 MEDIUM 7.2 HIGH
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue
CVE-2021-24553 1 Timeline Calendar Project 1 Timeline Calendar 2021-08-26 6.5 MEDIUM 7.2 HIGH
The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin
CVE-2021-24506 1 Quantumcloud 1 Slider Hero 2021-08-26 6.5 MEDIUM 8.8 HIGH
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.
CVE-2021-24554 1 Freelancetoindia 1 Paytm-pay 2021-08-26 6.5 MEDIUM 7.2 HIGH
The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue
CVE-2020-18746 1 Aitecms 1 Aitecms 2021-08-24 6.5 MEDIUM 7.2 HIGH
SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".
CVE-2020-22122 1 Find A Place Ljcms Project 1 Find A Place Ljcms 2021-08-24 5.0 MEDIUM 7.5 HIGH
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
CVE-2020-18877 1 Wuzhicms 1 Wuzhicms 2021-08-23 5.0 MEDIUM 7.5 HIGH
SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.
CVE-2021-24521 1 Wow-estore 1 Side Menu 2021-08-17 6.5 MEDIUM 7.2 HIGH
The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.
CVE-2013-4717 1 Otrs 2 Otrs, Otrs Itsm 2021-08-17 6.5 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Kernel/Output/HTML/PreferencesCustomQueue.pm, Kernel/System/CustomerCompany.pm, Kernel/System/Ticket/IndexAccelerator/RuntimeDB.pm, Kernel/System/Ticket/IndexAccelerator/StaticDB.pm, and Kernel/System/TicketSearch.pm.
CVE-2021-37614 1 Progress 1 Moveit Transfer 2021-08-17 6.5 MEDIUM 8.8 HIGH
In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or execute SQL statements that alter or delete database elements, via crafted strings sent to unique MOVEit Transfer transaction types. The fixed versions are 2019.0.7 (11.0.7), 2019.1.6 (11.1.6), 2019.2.3 (11.2.3), 2020.0.6 (12.0.6), 2020.1.5 (12.1.5), and 2021.0.3 (13.0.3).
CVE-2020-20981 1 Metinfo 1 Metinfo 2021-08-16 5.0 MEDIUM 7.5 HIGH
A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.
CVE-2021-24520 1 Coderstimes 1 Out Of Stock Message For Woocommerce 2021-08-16 6.5 MEDIUM 8.8 HIGH
The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, making it vulnerable to SQL Injection attacks. Users with a role of contributor or higher can exploit this vulnerability.
CVE-2020-28087 1 Jeecg 1 Jeecg Boot 2021-08-14 5.0 MEDIUM 7.5 HIGH
A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.
CVE-2021-25899 1 Void 1 Aurall Rec Monitor 2021-08-13 5.0 MEDIUM 7.5 HIGH
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1.
CVE-2021-36455 1 Naviwebs 1 Navigate Cms 2021-08-13 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php.
CVE-2021-38168 1 Roxy-wi 1 Roxy-wi 2021-08-12 6.5 MEDIUM 8.8 HIGH
Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.
CVE-2021-31867 1 Pimcore 1 Customer Management Framework 2021-08-12 5.0 MEDIUM 7.5 HIGH
Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was fixed in version 3.0.2 of the product.
CVE-2021-31869 1 Pimcore 1 Adminbundle 2021-08-12 5.0 MEDIUM 7.5 HIGH
Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the application. This issue was fixed in version 6.9.4 of the product.
CVE-2020-23150 1 Rconfig 1 Rconfig 2021-08-12 5.0 MEDIUM 7.5 HIGH
A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php.
CVE-2020-23149 1 Rconfig 1 Rconfig 2021-08-12 5.0 MEDIUM 7.5 HIGH
The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and access sensitive database information.
CVE-2021-32590 1 Fortinet 1 Fortiportal 2021-08-11 9.0 HIGH 8.8 HIGH
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests.
CVE-2020-29011 1 Fortinet 1 Fortisandbox 2021-08-10 6.5 MEDIUM 8.8 HIGH
Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.
CVE-2021-37557 1 Centreon 1 Centreon 2021-08-10 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.
CVE-2021-37556 1 Centreon 1 Centreon 2021-08-10 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end parameters.
CVE-2021-24484 1 Ays-pro 1 Secure Copy Content Protection And Content Locking 2021-08-10 6.5 MEDIUM 7.2 HIGH
The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVE-2021-24483 1 Ays-pro 1 Poll Maker 2021-08-10 6.5 MEDIUM 7.2 HIGH
The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVE-2021-24492 1 Handsome Testimonials \& Reviews Project 1 Handsome Testimonials \& Reviews 2021-08-10 6.5 MEDIUM 8.8 HIGH
The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue.
CVE-2021-24462 1 Ays-pro 1 Photo Gallery 2021-08-10 6.5 MEDIUM 8.8 HIGH
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVE-2021-24461 1 Ays-pro 1 Faq Builder 2021-08-10 6.5 MEDIUM 8.8 HIGH
The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVE-2021-24463 1 Ays-pro 1 Image Slider 2021-08-10 6.5 MEDIUM 8.8 HIGH
The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVE-2021-24460 1 Ays-pro 1 Popup Box 2021-08-10 6.5 MEDIUM 8.8 HIGH
The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard