| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. |
| ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC). |
| Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC). |
| Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. |
| Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. |
| Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions. |
| SQL injection in the Zalktis accounting application via
trading-partner-controlled text fields in received electronic invoices. When
importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis
concatenates partner-controlled values directly into SQL statement text using
string concatenation, with neither parameterised queries nor escaping. The
application's own escaping helper, Dazadi.sql_txt(),
is not invoked on these code paths, so a party that sends an invoice can break
out of the string literal and alter the query logic.
This issue affects Zalktis: before 2026.1.586 and before 2026.2.592. |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command. |
| Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutralization of special elements used in an SQL command. |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command. |
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. |
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. |
| Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. |
| Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. |
| Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. |
| Subscriber SQL Injection in Do Lasso <= 358 versions. |
| Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. |