Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9452 1 Nex-forms - Ultimate Form Builder Project 1 Nex-forms - Ultimate Form Builder 2019-10-08 7.5 HIGH 9.8 CRITICAL
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
CVE-2015-9451 1 Sizmic 1 Plugmatter Optin Feature Box 2019-10-08 7.5 HIGH 9.8 CRITICAL
The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.
CVE-2019-17197 1 Open-emr 1 Openemr 2019-10-08 7.5 HIGH 9.8 CRITICAL
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
CVE-2019-17049 1 Netgear 2 Srx5308, Srx5308 Firmware 2019-10-04 5.0 MEDIUM 7.5 HIGH
NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user account.
CVE-2019-16996 1 Metinfo 1 Metinfo 2019-10-04 6.5 MEDIUM 7.2 HIGH
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
CVE-2019-16997 1 Metinfo 1 Metinfo 2019-10-04 6.5 MEDIUM 7.2 HIGH
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
CVE-2019-13957 1 Umbraco 1 Umbraco 2019-10-04 7.5 HIGH 9.8 CRITICAL
In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.
CVE-2019-16744 1 Ebrigade 1 Ebrigade 2019-10-03 6.5 MEDIUM 8.8 HIGH
eBrigade before 5.0 has evenements.php cid SQL Injection.
CVE-2019-16745 1 Ebrigade 1 Ebrigade 2019-10-03 6.5 MEDIUM 8.8 HIGH
eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.
CVE-2018-17092 1 I4a 1 Donlinkage 2019-10-03 5.5 MEDIUM 5.4 MEDIUM
An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be exploited via specially crafted input, allowing an attacker to obtain information from a database. The vulnerability can only be triggered by an authorized user.
CVE-2018-8733 1 Nagios 1 Nagios Xi 2019-10-03 7.5 HIGH 9.8 CRITICAL
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.
CVE-2018-3783 1 Flintcms 1 Flintcms 2019-10-03 7.5 HIGH 9.8 CRITICAL
A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.
CVE-2017-1002004 1 Dtracker Project 1 Dtracker 2019-10-03 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
CVE-2017-3549 1 Oracle 1 Scripting 2019-10-03 7.5 HIGH 9.1 CRITICAL
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
CVE-2017-1002012 1 Anblik 1 Image-gallery-with-slideshow 2019-10-03 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.
CVE-2017-1002005 1 Dtracker Project 1 Dtracker 2019-10-03 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.
CVE-2017-15379 1 Softwarepublico 1 E-sic 2019-10-03 7.5 HIGH 9.8 CRITICAL
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
CVE-2019-16999 1 Idcos 1 Cloudboot 2019-10-02 7.5 HIGH 9.8 CRITICAL
CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI.
CVE-2019-16743 1 Ebrigade 1 Ebrigade 2019-10-02 6.5 MEDIUM 8.8 HIGH
eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.
CVE-2019-16692 1 Phpipam 1 Phpipam 2019-10-01 7.5 HIGH 9.8 CRITICAL
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
CVE-2015-9333 1 Cformsii Project 1 Cformsii 2019-09-30 7.5 HIGH 9.8 CRITICAL
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
CVE-2015-9446 1 Unitegallery 1 Unite Gallery Lite 2019-09-26 6.5 MEDIUM 8.8 HIGH
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
CVE-2018-17232 1 Slack Archivebot Project 1 Slack Archivebot 2019-09-26 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().
CVE-2015-9449 1 Efficientscripts 1 Microblog Poster 2019-09-26 6.5 MEDIUM 7.2 HIGH
The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=microblogposter.php account_id parameter.
CVE-2015-9448 1 Pressified 1 Sendpress 2019-09-26 6.5 MEDIUM 8.8 HIGH
The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.
CVE-2018-5989 1 Chillcreations 1 Ccnewsletter 2019-09-26 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099.
CVE-2019-16194 1 Centreon 1 Centreon 2019-09-25 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.
CVE-2019-16696 1 Phpipam 1 Phpipam 2019-09-23 7.5 HIGH 9.8 CRITICAL
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
CVE-2019-16694 1 Phpipam 1 Phpipam 2019-09-23 7.5 HIGH 9.8 CRITICAL
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
CVE-2019-16695 1 Phpipam 1 Phpipam 2019-09-23 7.5 HIGH 9.8 CRITICAL
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
CVE-2019-16693 1 Phpipam 1 Phpipam 2019-09-23 7.5 HIGH 9.8 CRITICAL
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
CVE-2015-9400 1 Typomedia 1 Wordpress Meta Robots 2019-09-20 6.5 MEDIUM 8.8 HIGH
The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.
CVE-2015-9399 1 Trivetechnology 1 Wp-stats-dashboard 2019-09-20 6.5 MEDIUM 7.2 HIGH
The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.
CVE-2019-16644 1 Tuzicms 1 Tuzicms 2019-09-20 7.5 HIGH 9.8 CRITICAL
App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring.
CVE-2015-9395 1 Usersultra 1 Users Ultra Membership 2019-09-20 6.5 MEDIUM 8.8 HIGH
The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.
CVE-2015-9398 1 Webmaster-source 1 Gocodes 2019-09-20 6.5 MEDIUM 8.8 HIGH
The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.
CVE-2019-16642 1 Yejiao 1 Tuzicms 2019-09-20 7.5 HIGH 9.8 CRITICAL
App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.
CVE-2016-11000 1 Smackcoders 1 Ultimate Exporter 2019-09-20 7.5 HIGH 9.8 CRITICAL
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
CVE-2019-15301 1 Terrasoft 1 Bpm Online Crm System Sdk 2019-09-19 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
CVE-2019-14254 1 Publisure 1 Publisure 2019-09-19 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL injections in userAccFunctions.php functions. Using this, an attacker can access passwords and/or grant access to the user account "user" in order to become "Administrator" (for example).
CVE-2019-16264 1 Egpp 1 Sistema Integrado De Gestion Academica 2019-09-17 7.5 HIGH 9.8 CRITICAL
In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the database.
CVE-2018-15873 1 Sapplica 1 Sentrifugo 2019-09-16 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.
CVE-2016-10949 1 Relevanssi 1 Relevanssi 2019-09-16 6.8 MEDIUM 8.8 HIGH
The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
CVE-2016-10951 1 Firestormplugins 1 Fs-shopping-cart 2019-09-16 6.5 MEDIUM 7.2 HIGH
The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.
CVE-2019-16309 1 Flamecms Project 1 Flamecms 2019-09-16 7.5 HIGH 9.8 CRITICAL
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
CVE-2016-10950 1 Sirv 1 Sirv 2019-09-16 6.5 MEDIUM 8.8 HIGH
The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
CVE-2017-18614 1 Wp-kama 1 Kama Click Counter 2019-09-16 9.3 HIGH 8.1 HIGH
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
CVE-2016-10942 1 Podlove 1 Podlove Podcast Publisher 2019-09-13 7.5 HIGH 9.8 CRITICAL
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.
CVE-2016-10940 1 Zm-gallery Project 1 Zm-gallery 2019-09-13 6.5 MEDIUM 7.2 HIGH
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
CVE-2016-10943 1 Zx-csv-upload Project 1 Zx-csv-upload 2019-09-13 6.5 MEDIUM 7.2 HIGH
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.