16621 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2015-20120
RealtyScript Database
8.8
HIGH
EPSS
0.5%
2015 CWE-89 2 PoCs

Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract database information by injecting SQL code into application parameters. Attackers can craft requests with time-delay payloads to infer database contents character by character based on response timing differences.

CVE-2015-20121
RealtyScripts Web Database
8.8
HIGH
EPSS
0.3%
2015 CWE-89 2 PoCs

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitrary SQL code through the GET parameter 'u_id' in /admin/users.php and the POST parameter 'agent[]' in /admin/mailer.php. Attackers can exploit time-based blind SQL injection techniques to extract sensitive database information or cause denial of service through sleep-based payloads.

CVE-2026-30711
Software Genérico Web Database
8.8
HIGH
EPSS
0.0%
2026 2 PoCs

Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer and user-agent.

CVE-2026-27179
MajorDoMo Web Database
8.8
HIGH
EPSS
0.0%
2026 CWE-89 1 PoC

MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands_search.inc.php file directly interpolates the $_GET['parent'] parameter into multiple SQL queries without sanitization or parameterized queries. The commands module is loadable without authentication via the /objects/?module=commands endpoint, which includes arbitrary modules by name and calls their usual() method. Time-based blind SQL injection is exploitable using UNION SELECT SLEEP() syntax. Because MajorDoMo stores admin passwords as unsalted MD5 hashes in the

CVE-2023-2719
SupportCandy Web Database Windows
8.8
HIGH
EPSS
4.3%
2023 2 PoCs

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

CVE-2023-28659
Waiting: One-click Countdowns WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
1.1%
2023 1 PoC

The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.

CVE-2023-23492
Login with Phone Number WordPress Plugin Web Database Windows ⚡ nuclei
8.8
HIGH
EPSS
88.3%
2023 1 PoC

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

CVE-2023-4776
School Management System Web Database Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

CVE-2023-5412
Image horizontal reel scroll slideshow Web Database Windows
8.8
HIGH
EPSS
9.8%
2023 CWE-89 1 PoC

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-0234
SiteGround Security Web Database Windows
8.8
HIGH
EPSS
6.7%
2023 1 PoC

The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.

CVE-2023-41504
Software Genérico Web Database
8.8
HIGH
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.

CVE-2023-26876
Software Genérico Web Database
8.8
HIGH
EPSS
54.1%
2023 2 PoCs

SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.

CVE-2023-26860
Software Genérico Database
8.8
HIGH
EPSS
0.5%
2023 1 PoC

SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component.

CVE-2023-39378
SiberianCMS Web Database
8.8
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unauthenticated user

CVE-2023-49546
Software Genérico Web Database
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.

CVE-2023-47460
Software Genérico Database
8.8
HIGH
EPSS
13.8%
2023 1 PoC

SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.

CVE-2023-2843
MultiParcels Shipping For WooCommerce Web Database Windows
8.8
HIGH
EPSS
0.4%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

CVE-2023-0259
WP Google Review Slider Web Database Windows
8.8
HIGH
EPSS
0.5%
2023 1 PoC

The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-49440
Software Genérico Database
8.8
HIGH
EPSS
0.0%
2023 2 PoCs

AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."

CVE-2023-5041
Track The Click Web Database Windows
8.8
HIGH
EPSS
0.3%
2023 1 PoC

The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.