CVE-2025-22964

CVSS v3 Score
8.1
High

Vulnerability Description

DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database queries without proper escaping or validation. Exploiting this issue enables unauthorized access, manipulation of data, or exposure of sensitive information, posing significant risks to the integrity and confidentiality of the application.

CVSS:8.1(High)

SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.

CWE-892015
CVSS:8.1(High)

SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.

CWE-892015
CVSS:8.1(High)

SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CWE-892015
CVSS:8.1(High)

Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbit...

CWE-892015
CVSS:8.1(High)

cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).

CWE-892016
CVSS:8.1(High)

SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to system...

CWE-892016