Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2025-01-29 CVE-2025-0803 SQL Injection vulnerability in Gymmanagementsystem GYM Management System 1.0
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0.
network
low complexity
gymmanagementsystem CWE-89
critical
9.8
2025-01-28 CVE-2024-11135 SQL Injection vulnerability in Imithemes Eventer
The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees' function in all versions up to, and including, 3.9.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
imithemes CWE-89
7.5
2025-01-28 CVE-2023-50316 SQL Injection vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2025-01-27 CVE-2024-54145 SQL Injection vulnerability in Cacti 1.2.27/1.2.28
Cacti is an open source performance and fault management framework.
network
low complexity
cacti CWE-89
8.8
2025-01-27 CVE-2024-54146 SQL Injection vulnerability in Cacti 1.2.27/1.2.28
Cacti is an open source performance and fault management framework.
network
low complexity
cacti CWE-89
8.8
2025-01-26 CVE-2024-10628 The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
CWE-89
7.5
2025-01-25 CVE-2024-35148 IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection.
network
low complexity
CWE-89
6.3
2025-01-24 CVE-2024-13594 SQL Injection vulnerability in Neofix Simple Downloads List
The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofix_sdl' shortcode in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
neofix CWE-89
6.5
2025-01-24 CVE-2024-13680 SQL Injection vulnerability in Codepeople Form Builder CP
The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in all versions up to, and including, 1.2.41 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
codepeople CWE-89
6.5
2025-01-23 CVE-2024-57328 SQL Injection vulnerability in Projectworlds Online Food Ordering System 1.0
A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0.
network
low complexity
projectworlds CWE-89
critical
9.8