Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24137 1 Adenion 1 Blog2social 2021-03-23 6.5 MEDIUM 8.8 HIGH
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.
CVE-2021-24149 1 Webnus 1 Modern Events Calendar Lite 2021-03-23 6.5 MEDIUM 8.8 HIGH
Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.
CVE-2020-5579 1 Strangerstudios 1 Paid Memberships Pro 2021-03-23 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
CVE-2021-22848 1 Hgiga 4 Msr45 Isherlock-antispam, Msr45 Isherlock-user, Ssr45 Isherlock-antispam and 1 more 2021-03-23 7.5 HIGH 9.8 CRITICAL
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
CVE-2021-22859 1 Eic 1 E-document System 2021-03-23 7.5 HIGH 9.8 CRITICAL
The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.
CVE-2021-20678 1 Paidmembershipspro 1 Paid Memberships Pro 2021-03-23 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2021-24139 1 10web 1 Photo Gallery 2021-03-22 7.5 HIGH 9.8 CRITICAL
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
CVE-2021-24140 1 Connekthq 1 Ajax Load More 2021-03-22 6.5 MEDIUM 7.2 HIGH
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.
CVE-2021-24141 1 Sigmaplugin 1 Advanced Database Cleaner 2021-03-22 6.5 MEDIUM 7.2 HIGH
Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.
CVE-2021-24143 1 Accesspressthemes 1 Accesspress Social Icons 2021-03-22 6.5 MEDIUM 8.8 HIGH
Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
CVE-2021-24142 1 Premiumwpsuite 1 Easy Redirect Manager 2021-03-22 6.5 MEDIUM 7.2 HIGH
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.
CVE-2021-28381 1 Vhs Project 1 Vhs 2021-03-22 7.5 HIGH 9.8 CRITICAL
The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper.
CVE-2020-24913 1 Qcubed 1 Qcubed 2021-03-22 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
CVE-2021-28295 1 Online Ordering System Project 1 Online Ordering System 2021-03-22 5.0 MEDIUM 7.5 HIGH
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.
CVE-2018-17254 1 Arkextensions 1 Jck Editor 2021-03-17 7.5 HIGH 9.8 CRITICAL
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
CVE-2021-27947 1 Mybb 1 Mybb 2021-03-16 6.5 MEDIUM 7.2 HIGH
SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).
CVE-2021-27948 1 Mybb 1 Mybb 2021-03-16 6.5 MEDIUM 7.2 HIGH
SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3).
CVE-2020-24877 1 Zzzcms 1 Zzzphp 2021-03-15 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
CVE-2021-27581 1 Kentico 1 Kentico Cms 2021-03-15 7.5 HIGH 9.8 CRITICAL
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
CVE-2021-23352 1 Madge Project 1 Madge 2021-03-12 7.5 HIGH 9.8 CRITICAL
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.