Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-03-15 CVE-2023-24728 SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.
8.8
2023-03-15 CVE-2023-24729 SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
8.8
2023-03-15 CVE-2023-24730 SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.
8.8
2023-03-15 CVE-2023-24731 SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.
8.8
2023-03-15 CVE-2023-24732 SQL Injection vulnerability in Simple Customer Relationship Management System Project Simple Customer Relationship Management System 1.0
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function.
8.8
2023-03-14 CVE-2023-25206 SQL Injection vulnerability in Prestashop Advanced Reviews
PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.
network
low complexity
prestashop CWE-89
8.8
2023-03-14 CVE-2023-27074 SQL Injection vulnerability in PHPgurukul BP Monitoring Management System 1.0
BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.
network
low complexity
phpgurukul CWE-89
critical
9.8
2023-03-13 CVE-2023-27052 SQL Injection vulnerability in Moosikay Project Moosikay 1.0
E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php.
network
low complexity
moosikay-project CWE-89
critical
9.8
2023-03-13 CVE-2023-25207 SQL Injection vulnerability in Prestashop DPD France
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
network
low complexity
prestashop CWE-89
critical
9.8
2023-03-10 CVE-2023-1198 SQL Injection vulnerability in Saysis Starcities 1.1/1.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection.This issue affects Starcities: through 1.3.
network
low complexity
saysis CWE-89
critical
9.8