CWE-707

Improper Neutralization

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

251 vulnerabilities with CWE-707
CVE-2022-4251 LOW
Movie Ticket Booking System - Cross-Site Scripting in editBooking.php
CVSS 2.4
CVE-2022-4250 LOW
Movie Ticket Booking System - Cross-Site Scripting via booking.php id Parameter
CVSS 3.5
CVE-2022-4249 LOW
Movie Ticket Booking System - Cross-Site Scripting via ORDER_ID Parameter
CVSS 3.5
CVE-2022-4248 MEDIUM
Movie Ticket Booking System - SQL Injection via editBooking.php id Parameter
CVSS 5.0
CVE-2022-4247 MEDIUM
Movie Ticket Booking System - SQL Injection via booking.php id Parameter
CVSS 6.3
CVE-2022-4234 LOW
Canteen Management System - Cross-Site Scripting in youthappam/brand.php via brand_name Argument
CVSS 3.5
CVE-2022-4233 LOW
SourceCodester Event Registration System 1.0 - Cross-Site Scripting via First Name/Last Name Argument
CVSS 2.4
CVE-2022-4222 MEDIUM
Canteen Management System - SQL Injection via ajax_invoice.php POST Request Handler
CVSS 5.0
CVE-2022-4091 LOW
SourceCodester Canteen Management System - XSS
CVSS 3.5
CVE-2022-4089 MEDIUM
rickxy Stock Management System - XSS
CVSS 4.3
CVE-2022-4088 HIGH
rickxy Stock Management System - SQL Injection
CVSS 7.3
CVE-2022-4064 LOW
dalli < 3.2.3 - Injection via Meta Protocol Handler cas/ttl Argument
CVSS 3.7
CVE-2022-4053 LOW
Student Attendance Management System - XSS
CVSS 2.4
CVE-2022-4052 MEDIUM
Student Attendance Management System - SQL Injection
CVSS 4.7
CVE-2022-4051 MEDIUM
Hostel Searching Project - SQL Injection
CVSS 6.3
CVE-2022-4015 MEDIUM
Sports Club Management System 119 - SQL Injection
CVSS 4.7
CVE-2022-4012 MEDIUM
Hospital Management Center - SQL Injection
CVSS 6.3
CVE-2022-4011 MEDIUM
Simple History Plugin - Info Disclosure
CVSS 6.5
CVE-2022-3998 MEDIUM
scm - SQL Injection via id Parameter in uredi_korisnika.php
CVSS 6.3
CVE-2022-3997 MEDIUM
MonikaBrzica scm - SQL Injection via email/lozinka/ime/id Parameters
CVSS 6.3
CVE-2022-3992 LOW
Sanitization Management System - Cross-Site Scripting in Banner Image Handler
CVSS 2.4
CVE-2022-3988 LOW
frappe < 14.14.3 - Cross-Site Scripting via Navbar Search Parameter
CVSS 3.5
CVE-2022-3975 LOW
NukeViet CMS < 4.5 - Cross-Site Scripting in Data URL Handler
CVSS 3.5
CVE-2022-3973 HIGH
hms-php - SQL Injection via Data Pump Metadata uname/pass Parameters
CVSS 7.3
CVE-2022-3972 HIGH
HMS-PHP - SQL Injection via admin/adminlogin.php uname/pass Parameters
CVSS 7.3
Details
Vulnerabilities 251