Vulnerabilities (CVE)

Filtered by CWE-89
Total 15971 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-4960 1 Silverstripe 1 Silverstripe 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2010-5287 1 Cstech 1 Webconductor 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-1521 1 Taskfreak 1 Taskfreak\! 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php.
CVE-2010-0970 1 Jorik Berkepas 1 Phpmylogon 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in phpmylogon.php in PhpMyLogon 2 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
CVE-2010-1426 1 Modxcms 1 Modxcms 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin.
CVE-2010-4915 1 Coldgen 1 Coldbookmarks 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action.
CVE-2010-5009 1 Ut-files 1 Utstats 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.
CVE-2010-2916 1 Ajsquare 1 Aj Hyip 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2011-5099 2 Chillcreations, Joomla 2 Mod Ccnewsletter, Joomla\! 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2011-5175 1 Bananadance 1 Banana Dance 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in search.php in Banana Dance, possibly B.1.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the category parameter.
CVE-2011-1048 1 Mihantools 1 Mihantools 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in product.php in MihanTools 1.33 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-1071 1 Phpmdj 1 Phpmdj 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in profil.php in phpMDJ 1.0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-5003 1 E-soft24 1 Banner Exchange Script 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
CVE-2010-2610 1 2daybiz 1 Job Site Script 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to show_search_result.php.
CVE-2010-4926 2 Joomla, Timetrack 2 Joomla\!, Com Timetrack 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ct_id parameter in a timetrack action to index.php.
CVE-2010-0693 1 Commodityrentals 1 Trade Manager Script 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2012-2601 1 Progress 1 Whatsup Gold 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute arbitrary SQL commands via the sGroupList parameter.
CVE-2010-1010 2 Matthias Kall, Typo3 2 Mk Wastebasket, Typo3 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the MK Wastebasket (mk_wastebasket) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2013-4137 1 Status 1 Statusnet 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
CVE-2010-1073 2 Joomla, Joshprakash 2 Joomla\!, Com Jembed 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php.