Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-36217: Release XOOPS Version 2.5.10 Final · XOOPS/XoopsCore25

Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.

CVE
#sql#xss#vulnerability#php
CVE-2023-36213: OffSec’s Exploit Database Archive

SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.

CVE-2023-33366: CVE-2023-33366

A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitrary SQL commands.

CVE-2023-36299: Release v1.2.1 · typecho/typecho

A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.

CVE-2023-4136: Security Advisories — CrafterCMS 4.0.7 documentation

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.

WordPress Adivaha Travel 2.3 SQL Injection

WordPress Adivaha Travel plugin version 2.3 suffers from a remote SQL injection vulnerability.

PHPJabbers Bus Reservation System 1.1 SQL Injection

PHPJabbers Bus Reservation System version 1.1 suffers from a remote SQL injection vulnerability.

OX App Suite SSRF / SQL Injection / Cross Site Scripting

OX App Suite suffers from remote SQL injection, server-side request forgery, cross site scripting, improper neutralization, command injection, and exposure of sensitive information vulnerabilities.

Academy LMS 6.0 Cross Site Scripting

Academy LMS version 6.0 suffers from a cross site scripting vulnerability.

PHPJabbers Rental Property Booking 2.0 Cross Site Scripting

PHPJabbers Rental Property Booking version 2.0 suffers from a cross site scripting vulnerability.