Explore CVEs related to SQL Injection vulnerabilities, filtered by published year. This list is sorted by most recent disclosures first and supports filtering by CVSS and EPSS risk scores.
Includes the most recent vulnerability disclosures and trends, helping security teams quickly identify high-risk issues and exploitation likelihood.
You're viewing SQL Injection CVEs published in 2018. View full CVE list
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2018-18705 | PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php. | 9.8 | 1.97% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18704 | PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter. | 9.8 | 1.59% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18702 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. | 9.8 | 1.45% | 2018-10-29 | 2026-06-16 |
| CVE-2016-10731 | ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action. | 9.8 | 1.42% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18476 | mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns. | 9.8 | 1.79% | 2018-10-24 | 2026-06-16 |
| CVE-2018-17446 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | 9.8 | 1.96% | 2018-10-23 | 2026-06-16 |
| CVE-2018-18550 | ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user. | 8.8 | 0.93% | 2018-10-21 | 2026-06-16 |
| CVE-2018-18546 | ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable. | 9.8 | 1.66% | 2018-10-20 | 2026-06-16 |
| CVE-2018-18530 | ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI. | 9.8 | 1.20% | 2018-10-19 | 2026-06-16 |
| CVE-2018-18529 | ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI. | 9.8 | 1.20% | 2018-10-19 | 2026-06-16 |
| CVE-2018-18527 | OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter. | 9.8 | 1.59% | 2018-10-19 | 2026-06-16 |
| CVE-2018-18488 | In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter. | 9.8 | 1.14% | 2018-10-18 | 2026-06-16 |
| CVE-2018-18486 | An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter. | 9.8 | 1.14% | 2018-10-18 | 2026-06-16 |
| CVE-2015-4633 | Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface. | 9.8 | 6.02% | 2018-10-18 | 2026-06-16 |
| CVE-2018-18450 | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI. | 9.8 | 1.52% | 2018-10-17 | 2026-06-16 |
| CVE-2018-18427 | s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php. | 9.8 | 1.19% | 2018-10-17 | 2026-06-16 |
| CVE-2018-15755 | Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server. | 6.6 | 1.28% | 2018-10-12 | 2026-06-16 |
| CVE-2018-18242 | youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86. | 9.8 | 1.14% | 2018-10-11 | 2026-06-16 |
| CVE-2018-18211 | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI. | 8.1 | 0.88% | 2018-10-10 | 2026-06-16 |
| CVE-2018-18200 | There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4. | 9.8 | 1.42% | 2018-10-09 | 2026-06-16 |