CWE-707
Improper Neutralization
The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.
251 vulnerabilities with CWE-707
CVE-2022-4251
LOW
Movie Ticket Booking System - Cross-Site Scripting in editBooking.php
CVSS 2.4
CVE-2022-4250
LOW
Movie Ticket Booking System - Cross-Site Scripting via booking.php id Parameter
CVSS 3.5
CVE-2022-4249
LOW
Movie Ticket Booking System - Cross-Site Scripting via ORDER_ID Parameter
CVSS 3.5
CVE-2022-4248
MEDIUM
Movie Ticket Booking System - SQL Injection via editBooking.php id Parameter
CVSS 5.0
CVE-2022-4247
MEDIUM
Movie Ticket Booking System - SQL Injection via booking.php id Parameter
CVSS 6.3
CVE-2022-4234
LOW
Canteen Management System - Cross-Site Scripting in youthappam/brand.php via brand_name Argument
CVSS 3.5
CVE-2022-4233
LOW
SourceCodester Event Registration System 1.0 - Cross-Site Scripting via First Name/Last Name Argument
CVSS 2.4
CVE-2022-4222
MEDIUM
Canteen Management System - SQL Injection via ajax_invoice.php POST Request Handler
CVSS 5.0
CVE-2022-4091
LOW
SourceCodester Canteen Management System - XSS
CVSS 3.5
CVE-2022-4089
MEDIUM
rickxy Stock Management System - XSS
CVSS 4.3
CVE-2022-4088
HIGH
rickxy Stock Management System - SQL Injection
CVSS 7.3
CVE-2022-4064
LOW
dalli < 3.2.3 - Injection via Meta Protocol Handler cas/ttl Argument
CVSS 3.7
CVE-2022-4053
LOW
Student Attendance Management System - XSS
CVSS 2.4
CVE-2022-4052
MEDIUM
Student Attendance Management System - SQL Injection
CVSS 4.7
CVE-2022-4051
MEDIUM
Hostel Searching Project - SQL Injection
CVSS 6.3
CVE-2022-4015
MEDIUM
Sports Club Management System 119 - SQL Injection
CVSS 4.7
CVE-2022-4012
MEDIUM
Hospital Management Center - SQL Injection
CVSS 6.3
CVE-2022-4011
MEDIUM
Simple History Plugin - Info Disclosure
CVSS 6.5
CVE-2022-3998
MEDIUM
scm - SQL Injection via id Parameter in uredi_korisnika.php
CVSS 6.3
CVE-2022-3997
MEDIUM
MonikaBrzica scm - SQL Injection via email/lozinka/ime/id Parameters
CVSS 6.3
CVE-2022-3992
LOW
Sanitization Management System - Cross-Site Scripting in Banner Image Handler
CVSS 2.4
CVE-2022-3988
LOW
frappe < 14.14.3 - Cross-Site Scripting via Navbar Search Parameter
CVSS 3.5
CVE-2022-3975
LOW
NukeViet CMS < 4.5 - Cross-Site Scripting in Data URL Handler
CVSS 3.5
CVE-2022-3973
HIGH
hms-php - SQL Injection via Data Pump Metadata uname/pass Parameters
CVSS 7.3
CVE-2022-3972
HIGH
HMS-PHP - SQL Injection via admin/adminlogin.php uname/pass Parameters
CVSS 7.3
Details
Vulnerabilities
251