Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-10951 | 1 Firestormplugins | 1 Fs-shopping-cart | 2019-09-16 | 6.5 MEDIUM | 7.2 HIGH |
The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter. | |||||
CVE-2019-16309 | 1 Flamecms Project | 1 Flamecms | 2019-09-16 | 7.5 HIGH | 9.8 CRITICAL |
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. | |||||
CVE-2016-10950 | 1 Sirv | 1 Sirv | 2019-09-16 | 6.5 MEDIUM | 8.8 HIGH |
The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter. | |||||
CVE-2017-18614 | 1 Wp-kama | 1 Kama Click Counter | 2019-09-16 | 9.3 HIGH | 8.1 HIGH |
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter. | |||||
CVE-2016-10942 | 1 Podlove | 1 Podlove Podcast Publisher | 2019-09-13 | 7.5 HIGH | 9.8 CRITICAL |
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF. | |||||
CVE-2016-10940 | 1 Zm-gallery Project | 1 Zm-gallery | 2019-09-13 | 6.5 MEDIUM | 7.2 HIGH |
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter. | |||||
CVE-2016-10943 | 1 Zx-csv-upload Project | 1 Zx-csv-upload | 2019-09-13 | 6.5 MEDIUM | 7.2 HIGH |
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter. | |||||
CVE-2016-10939 | 1 Xtremelocator | 1 Xtremelocator | 2019-09-13 | 6.5 MEDIUM | 7.2 HIGH |
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter. | |||||
CVE-2016-10947 | 1 Post Indexer Project | 1 Post Indexer | 2019-09-13 | 6.5 MEDIUM | 7.2 HIGH |
The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin. | |||||
CVE-2019-5991 | 1 Cybozu | 1 Garoon | 2019-09-13 | 6.5 MEDIUM | 7.6 HIGH |
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2019-5996 | 1 Panasonic | 1 Video Insight Vms | 2019-09-13 | 6.5 MEDIUM | 8.8 HIGH |
SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2017-18597 | 1 Jtrt Responsive Tables Project | 1 Jtrt Responsive Tables | 2019-09-10 | 6.5 MEDIUM | 8.8 HIGH |
The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter. | |||||
CVE-2017-18602 | 1 Ibps Online Exam Project | 1 Ibps Online Exam | 2019-09-10 | 6.5 MEDIUM | 8.8 HIGH |
The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter. | |||||
CVE-2019-10671 | 1 Librenms | 1 Librenms | 2019-09-10 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter. | |||||
CVE-2019-12465 | 1 Librenms | 1 Librenms | 2019-09-10 | 5.5 MEDIUM | 8.1 HIGH |
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.php?debug=1&term= request. | |||||
CVE-2015-9353 | 1 Tri | 1 Gigpress | 2019-09-09 | 6.5 MEDIUM | 7.2 HIGH |
The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066. | |||||
CVE-2019-16125 | 1 Jobberbase | 1 Jobberbase | 2019-09-09 | 7.5 HIGH | 9.8 CRITICAL |
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection. | |||||
CVE-2015-9301 | 1 W3eden | 1 Live Forms | 2019-09-09 | 7.5 HIGH | 9.8 CRITICAL |
The liveforms plugin before 3.2.0 for WordPress has SQL injection. | |||||
CVE-2019-13191 | 1 Mapsolutions | 1 Intramaps | 2019-09-05 | 5.0 MEDIUM | 7.5 HIGH |
A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page. | |||||
CVE-2019-15872 | 1 Wpbrigade | 1 Loginpress | 2019-09-05 | 7.5 HIGH | 9.8 CRITICAL |
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. |