Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24778 1 Wpaffiliatefeed 1 Tradetracker-store 2022-03-11 6.5 MEDIUM 7.2 HIGH
The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
CVE-2021-24777 1 Hotscot 1 Contact Form 2022-03-11 6.5 MEDIUM 7.2 HIGH
The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection.
CVE-2022-0754 1 Salesagility 1 Suitecrm 2022-03-11 4.0 MEDIUM 6.5 MEDIUM
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
CVE-2022-0439 1 Icegram 1 Email Subscribers \& Newsletters 2022-03-11 6.5 MEDIUM 8.8 HIGH
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.
CVE-2022-0434 1 A3rev 1 Page View Count 2022-03-11 7.5 HIGH 9.8 CRITICAL
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks
CVE-2022-0420 1 Metagauss 1 Registrationmagic 2022-03-11 6.5 MEDIUM 7.2 HIGH
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks
CVE-2022-26201 1 Victor Cms Project 1 Victor Cms 2022-03-10 7.5 HIGH 9.8 CRITICAL
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
CVE-2021-40635 1 Os4ed 1 Opensis 2022-03-09 5.0 MEDIUM 7.5 HIGH
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.
CVE-2021-40636 1 Os4ed 1 Opensis 2022-03-09 5.0 MEDIUM 7.5 HIGH
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
CVE-2022-23899 1 Mingsoft 1 Mcms 2022-03-09 7.5 HIGH 9.8 CRITICAL
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
CVE-2022-23898 1 Mingsoft 1 Mcms 2022-03-09 7.5 HIGH 9.8 CRITICAL
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
CVE-2022-25125 1 Mingsoft 1 Mcms 2022-03-09 7.5 HIGH 9.8 CRITICAL
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
CVE-2021-43077 1 Fortinet 1 Fortiwlm 2022-03-09 6.5 MEDIUM 8.8 HIGH
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the AP monitor handlers.
CVE-2022-23387 1 Taocms 1 Taocms 2022-03-09 5.0 MEDIUM 7.5 HIGH
An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment Update field.
CVE-2022-23380 1 Taogogo 1 Taocms 2022-03-08 6.5 MEDIUM 8.8 HIGH
There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.
CVE-2022-24571 1 Car Driving School Management System Project 1 Car Driving School Management System 2022-03-08 7.5 HIGH 9.8 CRITICAL
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
CVE-2022-23911 1 Accesspressthemes 1 Ap Custom Testimonial 2022-03-08 6.5 MEDIUM 7.2 HIGH
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection
CVE-2022-0412 1 Templateinvaders 1 Ti Woocommerce Wishlist 2022-03-08 7.5 HIGH 9.8 CRITICAL
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks
CVE-2022-0411 1 Asgaros 1 Asgaros Forum 2022-03-08 6.5 MEDIUM 8.8 HIGH
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection
CVE-2022-0383 1 Ljapps 1 Wp Review Slider 2022-03-08 6.5 MEDIUM 7.2 HIGH
The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks