Vulnerabilities (CVE)

Filtered by CWE-89
Total 15522 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-2563 1 Vastal 1 Phpvid 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9 and 1.2.3 allows remote attackers to execute arbitrary SQL commands via the order_by parameter. NOTE: The cat parameter vector is already covered by CVE-2008-4157.
CVE-2014-1455 1 Pearson 1 Esis Enterprise Student Information System 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 and earlier, allows remote attackers to execute arbitrary SQL commands via the new password.
CVE-2014-3992 1 Dolibarr 1 Dolibarr Erp\/crm 2025-04-12 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity parameter in an update action to user/fiche.php or (2) sortorder parameter to user/group/index.php.
CVE-2015-6829 1 Ciphercoin 1 Wp Limit Login Attempts 2025-04-12 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the getip function in wp-limit-login-attempts.php in the WP Limit Login Attempts plugin before 2.0.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header.
CVE-2016-1000124 1 Huge-it 1 Portfolio Gallery 2025-04-12 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CVE-2013-3081 1 Jojocms 1 Jojo-cms 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header to /articles/test/.
CVE-2016-1000113 1 Huge-it 1 Gallery 2025-04-12 7.5 HIGH 9.8 CRITICAL
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
CVE-2012-1665 1 Oscmax 1 Oscmax 2025-04-12 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/login.php or (2) remote administrators to execute arbitrary SQL commands via the status parameter to admin/stats_monthly_sales.php or (3) country parameter in a process action to admin/create_account_process.php.
CVE-2015-4066 1 Tri 1 Gigpress 2025-04-12 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) show_artist_id or (2) show_venue_id parameter in an add action in the gigpress.php page to wp-admin/admin.php.
CVE-2015-8369 1 Cacti 1 Cacti 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.
CVE-2014-5183 1 Simple Retail Menus Plugin Project 1 Simple-retail-menus 2025-04-12 6.5 MEDIUM N/A
SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1 for WordPress allows remote authenticated editors to execute arbitrary SQL commands via the targetmenu parameter in an edit action to wp-admin/admin.php.
CVE-2015-5308 1 Wp-championship Project 1 Wp-championship 2025-04-12 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in cs_admin_users.php in the wp-championship plugin 5.8 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user, (2) isadmin, (3) mail service, (4) mailresceipt, (5) stellv, (6) champtipp, (7) tippgroup, or (8) userid parameter.
CVE-2015-1000011 1 Dukapress Project 1 Dukapress 2025-04-12 7.5 HIGH 9.8 CRITICAL
Blind SQL Injection in wordpress plugin dukapress v2.5.9
CVE-2015-4137 1 Milw0rm Project 1 Milw0rm Clone Script 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter.
CVE-2014-4649 1 Piwigo 1 Piwigo 2025-04-12 6.5 MEDIUM N/A
SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.
CVE-2016-1000118 1 Huge-it 1 Slideshow 2025-04-12 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1393 1 Cisco 1 Cloud Network Automation Provisioner 2025-04-12 6.5 MEDIUM 7.1 HIGH
SQL injection vulnerability in Cisco Cloud Network Automation Provisioner (CNAP) 1.0 and 1.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy72175.
CVE-2014-9173 1 Google Doc Embedder Project 1 Google Doc Embedder 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.
CVE-2016-8906 1 Dotcms 1 Dotcms 2025-04-12 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
CVE-2015-1055 1 10web 1 Photo Gallery 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.