Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15534 1 Raml-module-builder Project 1 Raml-module-builder 2019-08-26 7.5 HIGH 9.8 CRITICAL
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
CVE-2017-18573 1 Simplerealtytheme 1 Simple Login Log 2019-08-26 7.5 HIGH 9.8 CRITICAL
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
CVE-2017-18571 1 Search Everything Project 1 Search Everything 2019-08-26 7.5 HIGH 9.8 CRITICAL
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.
CVE-2016-10921 1 Ays-pro 1 Photo Gallery 2019-08-26 7.5 HIGH 9.8 CRITICAL
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
CVE-2016-10916 1 Codepeople 1 Appointment Booking Calendar 2019-08-26 7.5 HIGH 9.8 CRITICAL
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
CVE-2015-9335 1 Bestwebsoft 1 Limit Attempts 2019-08-26 7.5 HIGH 9.8 CRITICAL
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
CVE-2016-10917 1 Search Everything Project 1 Search Everything 2019-08-26 7.5 HIGH 9.8 CRITICAL
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.
CVE-2017-18570 1 Cformsii Project 1 Cformsii 2019-08-23 7.5 HIGH 9.8 CRITICAL
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
CVE-2014-10379 1 Duplicate Post Project 1 Duplicate Post 2019-08-22 7.5 HIGH 9.8 CRITICAL
The duplicate-post plugin before 2.6 for WordPress has SQL injection.
CVE-2015-9330 1 Soflyy 1 Wp All Import 2019-08-22 7.5 HIGH 9.8 CRITICAL
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
CVE-2019-1010034 1 Deepsoft 1 Weblibrarian 2019-08-21 4.0 MEDIUM 6.5 MEDIUM
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerable to a boolean-based blind sql injection. This function call can be triggered by any user logged-in with at least Volunteer role or manage_circulation capabilities. PoC : /wordpress/wp-admin/admin.php?page=weblib-circulation-desk&orderby=title&order=DESC.
CVE-2015-9325 1 Bestwebsoft 1 Visitors Online 2019-08-21 7.5 HIGH 9.8 CRITICAL
The visitors-online plugin before 0.4 for WordPress has SQL injection.
CVE-2016-10904 1 Olimometer Project 1 Olimometer 2019-08-21 7.5 HIGH 9.8 CRITICAL
The olimometer plugin before 2.57 for WordPress has SQL injection.
CVE-2015-9326 1 Wpbusinessintelligence 1 Wp Business Intelligence 2019-08-21 7.5 HIGH 9.8 CRITICAL
The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
CVE-2016-10909 1 Codepeople 1 Booking Calendar Contact Form 2019-08-21 7.5 HIGH 9.8 CRITICAL
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
CVE-2014-10376 1 Themeist 1 I Recommend This 2019-08-21 7.5 HIGH 9.8 CRITICAL
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
CVE-2019-15025 1 Ninjaforms 1 Ninjaforms 2019-08-20 7.5 HIGH 9.8 CRITICAL
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
CVE-2015-9310 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2019-08-19 7.5 HIGH 9.8 CRITICAL
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
CVE-2016-10888 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2019-08-19 7.5 HIGH 9.8 CRITICAL
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
CVE-2016-10887 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2019-08-19 7.5 HIGH 9.8 CRITICAL
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.