Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24778 | 1 Wpaffiliatefeed | 1 Tradetracker-store | 2022-03-11 | 6.5 MEDIUM | 7.2 HIGH |
The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. | |||||
CVE-2021-24777 | 1 Hotscot | 1 Contact Form | 2022-03-11 | 6.5 MEDIUM | 7.2 HIGH |
The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection. | |||||
CVE-2022-0754 | 1 Salesagility | 1 Suitecrm | 2022-03-11 | 4.0 MEDIUM | 6.5 MEDIUM |
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5. | |||||
CVE-2022-0439 | 1 Icegram | 1 Email Subscribers \& Newsletters | 2022-03-11 | 6.5 MEDIUM | 8.8 HIGH |
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link. | |||||
CVE-2022-0434 | 1 A3rev | 1 Page View Count | 2022-03-11 | 7.5 HIGH | 9.8 CRITICAL |
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks | |||||
CVE-2022-0420 | 1 Metagauss | 1 Registrationmagic | 2022-03-11 | 6.5 MEDIUM | 7.2 HIGH |
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks | |||||
CVE-2022-26201 | 1 Victor Cms Project | 1 Victor Cms | 2022-03-10 | 7.5 HIGH | 9.8 CRITICAL |
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. | |||||
CVE-2021-40635 | 1 Os4ed | 1 Opensis | 2022-03-09 | 5.0 MEDIUM | 7.5 HIGH |
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database. | |||||
CVE-2021-40636 | 1 Os4ed | 1 Opensis | 2022-03-09 | 5.0 MEDIUM | 7.5 HIGH |
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database. | |||||
CVE-2022-23899 | 1 Mingsoft | 1 Mcms | 2022-03-09 | 7.5 HIGH | 9.8 CRITICAL |
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java. | |||||
CVE-2022-23898 | 1 Mingsoft | 1 Mcms | 2022-03-09 | 7.5 HIGH | 9.8 CRITICAL |
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. | |||||
CVE-2022-25125 | 1 Mingsoft | 1 Mcms | 2022-03-09 | 7.5 HIGH | 9.8 CRITICAL |
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. | |||||
CVE-2021-43077 | 1 Fortinet | 1 Fortiwlm | 2022-03-09 | 6.5 MEDIUM | 8.8 HIGH |
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the AP monitor handlers. | |||||
CVE-2022-23387 | 1 Taocms | 1 Taocms | 2022-03-09 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment Update field. | |||||
CVE-2022-23380 | 1 Taogogo | 1 Taocms | 2022-03-08 | 6.5 MEDIUM | 8.8 HIGH |
There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit. | |||||
CVE-2022-24571 | 1 Car Driving School Management System Project | 1 Car Driving School Management System | 2022-03-08 | 7.5 HIGH | 9.8 CRITICAL |
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access. | |||||
CVE-2022-23911 | 1 Accesspressthemes | 1 Ap Custom Testimonial | 2022-03-08 | 6.5 MEDIUM | 7.2 HIGH |
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection | |||||
CVE-2022-0412 | 1 Templateinvaders | 1 Ti Woocommerce Wishlist | 2022-03-08 | 7.5 HIGH | 9.8 CRITICAL |
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks | |||||
CVE-2022-0411 | 1 Asgaros | 1 Asgaros Forum | 2022-03-08 | 6.5 MEDIUM | 8.8 HIGH |
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection | |||||
CVE-2022-0383 | 1 Ljapps | 1 Wp Review Slider | 2022-03-08 | 6.5 MEDIUM | 7.2 HIGH |
The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks |