Vulnerabilities (CVE)

Filtered by CWE-89
Total 14188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13409 1 Topmeeting 1 Topmeeting 2019-10-22 5.0 MEDIUM 9.8 CRITICAL
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.
CVE-2019-16682 1 Url Redirect Project 1 Url Redirect 2019-10-21 7.5 HIGH 7.3 HIGH
The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection.
CVE-2019-17612 1 74cms 1 74cms 2019-10-17 6.5 MEDIUM 7.2 HIGH
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVE-2015-9466 1 Webtechideas 1 Wti Like Post 2019-10-17 7.5 HIGH 9.8 CRITICAL
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
CVE-2019-17553 1 Metinfo 1 Metinfo 2019-10-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
CVE-2019-17552 1 Idreamsoft 1 Icms 2019-10-16 7.5 HIGH 9.8 CRITICAL
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
CVE-2019-17580 1 Dormsystem Project 1 Dormsystem 2019-10-16 7.5 HIGH 9.8 CRITICAL
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
CVE-2015-9465 1 Yet Another Stars Rating Project 1 Yet Another Stars Rating 2019-10-15 6.5 MEDIUM 8.8 HIGH
The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter.
CVE-2015-9460 1 Pinpoint 1 Pinpoint Booking System 2019-10-15 6.5 MEDIUM 8.8 HIGH
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
CVE-2019-10757 1 Knexjs 1 Knex 2019-10-15 7.5 HIGH 9.8 CRITICAL
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
CVE-2015-9462 1 Awesome Filterable Portfolio Project 1 Awesome Filterable Portfolio 2019-10-15 6.5 MEDIUM 7.2 HIGH
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.
CVE-2019-17429 1 Adhouma Cms Project 1 Adhouma Cms 2019-10-11 7.5 HIGH 9.8 CRITICAL
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
CVE-2019-17128 1 Netreo 1 Omnicenter 2019-10-11 5.0 MEDIUM 7.5 HIGH
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read sensitive information from the database used by the application.
CVE-2015-9467 1 K-78 1 Broken Link Manager 2019-10-11 7.5 HIGH 9.8 CRITICAL
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
CVE-2015-9461 1 Brinidesigner 1 Awesome Filterable Portfolio 2019-10-11 6.5 MEDIUM 7.2 HIGH
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter.
CVE-2015-9458 1 Seo Searchterms Tagging 2 Project 1 Seo Searchterms Tagging 2 2019-10-11 6.5 MEDIUM 7.2 HIGH
The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms count parameter exploitable via CSRF.
CVE-2015-9454 1 Slidervilla 1 Smooth Slider 2019-10-10 6.5 MEDIUM 8.8 HIGH
The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id parameter.
CVE-2019-17072 1 Awplife 1 Contact Form Widget 2019-10-10 7.5 HIGH 9.8 CRITICAL
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
CVE-2019-17418 1 Metinfo 1 Metinfo 2019-10-10 6.5 MEDIUM 7.2 HIGH
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
CVE-2019-17419 1 Metinfo 1 Metinfo 2019-10-10 6.5 MEDIUM 7.2 HIGH
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.