16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2023-2492
QueryWall: Plug'n Play Firewall Web Networking Database Windows
7.2
HIGH
EPSS
0.2%
2023 2 PoCs

The QueryWall: Plug'n Play Firewall WordPress plugin through 1.1.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2022-4355
LetsRecover Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2025-22210
Hikashop component for Joomla Web Database
7.2
HIGH
EPSS
0.1%
2025 CWE-89 1 PoC

A SQL injection vulnerability in the Hikashop component versions 3.3.0-5.1.4 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the category management area in backend.

CVE-2023-6620
POST SMTP Mailer Web Database Windows
7.2
HIGH
EPSS
3.4%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-24685
Software Genérico Database
7.2
HIGH
EPSS
0.4%
2023 1 PoC

ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.

CVE-2022-3300
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Web Database Windows
7.2
HIGH
EPSS
0.8%
2022 CWE-89 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2019-25703
ImpressCMS Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values containing SQL commands to extract sensitive database information.

CVE-2019-25664
SuiteCRM Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive database information through time-based blind SQL injection techniques.

CVE-2019-25693
ResourceSpace Web Database
7.1
HIGH
EPSS
0.0%
2019 CWE-352 1 PoC

ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keywords parameter in collection_edit.php. Attackers can submit POST requests with crafted SQL payloads in the keywords field to extract sensitive database information including schema names, user credentials, and other confidential data.

CVE-2019-25699
Newsbull Haber Script Database
7.1
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

Newsbull Haber Script 1.0.0 contains multiple SQL injection vulnerabilities in the search parameter that allow authenticated attackers to extract database information through time-based, blind, and boolean-based injection techniques. Attackers can inject malicious SQL code through the search parameter in endpoints like /admin/comment/records, /admin/category/records, /admin/news/records, and /admin/menu/childs to manipulate database queries and retrieve sensitive data.

CVE-2019-25638
Meeplace Business Review Script Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the addclick.php endpoint with crafted SQL payloads in the 'id' parameter to extract sensitive database information or cause denial of service.

CVE-2019-25529
Placeto CMS Web Database
7.1
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'page' parameter. Attackers can send GET requests to the admin/edit.php endpoint with malicious 'page' values using boolean-based blind, time-based blind, or union-based techniques to extract sensitive database information.

CVE-2019-25299
AhadPOS Database
7.1
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers to manipulate database queries through crafted POST requests. Attackers can exploit time-based and boolean-based blind SQL injection techniques to extract information or potentially interact with the underlying database.

CVE-2019-25303
contentManagementSystem Database
7.1
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to extract or manipulate database information by crafting malicious query payloads.

CVE-2019-25473
Clinic Pro Database
7.1
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month parameter. Attackers can send POST requests to the monthly_expense_overview endpoint with crafted month values using boolean-based blind, time-based blind, or error-based SQL injection techniques to extract sensitive database information.

CVE-2019-25347
thesystem Database
7.1
HIGH
EPSS
0.2%
2019 CWE-89 1 PoC

thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts.

CVE-2019-25300
Globitek CMS Web Database
7.1
HIGH
EPSS
0.0%
2019 CWE-89 1 PoC

thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or modify database information.

CVE-2019-25573
Green CMS Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cat parameter. Attackers can send GET requests to index.php with m=admin, c=posts, a=index parameters and inject SQL code in the cat parameter to manipulate database queries and extract sensitive information.

CVE-2019-2386
MongoDB Server Database
7.1
HIGH
EPSS
0.4%
2019 CWE-285 1 PoC

After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects MongoDB Server v4.0 versions prior to 4.0.9; MongoDB Server v3.6 versions prior to 3.6.13 and MongoDB Server v3.4 versions prior to 3.4.22. Workaround: After deleting one or more users, restart any nodes which may have had active user authorization sessions. Refrain from creating user accounts with the same name as previously deleted accounts.

CVE-2019-25450
Dolibarr ERP/CRM Web Database
7.1
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques.