
CVE-2024-41802 : XIBOSIGNAGE XIBO-CMS UP TO 3.3.11/4.0.13 API ROUTE SQL INJECTION
Description Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the
Description Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the
Description A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This issue affects some
Description A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical. This vulnerability affects
Description ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated
Description 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some
Description SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote
Description SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to
Description NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types implementing ILiteralType.ObjectToSQLString.
Description The Houzez Theme – Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all
Description A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an
Description The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is
Description Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A
Description Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
Description The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the
Description A vulnerability was found in SeaCMS 12.9. It has been declared as critical. Affected by this vulnerability is an
Description A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by
Description The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in
Description A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This vulnerability
Description DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to
Description The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard
Description The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘MerchantReference’
Description A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is
Description SQL injection vulnerability in PrestaShop opartdevis v.4.5.18 thru v.4.6.12 allows a remote attacker to execute arbitrary code via a
Description Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed