Vulnerabilities (CVE)

Filtered by CWE-89
Total 18762 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6852 2 Joomla, Markus Donhauser 2 Joomla\!, Ice Gallery Component For Joomla 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
CVE-2008-1316 1 Qt-cute 1 Quicktalk Forum 2026-04-23 6.8 MEDIUM N/A
SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3512 1 Php Nuke 1 Kleinanzeigen Module 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in the Kleinanzeigen module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a visit action to modules.php.
CVE-2009-2128 1 Elvinbts 1 Elvinbts 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the title (aka subject) field.
CVE-2008-4516 1 Galerie 1 Galerie 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via the pic parameter.
CVE-2009-3217 1 Wiccle 1 Iwiccle 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.
CVE-2009-3543 1 Phenotype-cms 1 Phenotype Cms 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name).
CVE-2008-3753 1 Yourfreeworld 1 Programs Rating Script 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in details.php in YourFreeWorld Programs Rating Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-0733 1 Cs Team 1 Counter Strike Portal 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in index.php in CS Team Counter Strike Portals allows remote attackers to execute arbitrary SQL commands via the id parameter, as demonstrated using the downloads page.
CVE-2008-5921 1 Umerinc 1 Songs Portal 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-1913 1 Lasernet Cms 1 Lasernet Cms 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the new parameter in a new action.
CVE-2009-1023 1 Phpcomasy 1 Phpcomasy 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in index.php in phpComasy 0.9.1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter.
CVE-2008-5054 1 Develop It Easy 1 Membership System 2026-04-23 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters to customer_login.php and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information.
CVE-2007-4953 1 Simpcms 1 Simpcms 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the keyword parameter in a search site action.
CVE-2008-3752 1 Yourfreeworld 1 Ad-exchange Script 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-3361 1 Paul Gibbs 1 Php-ipnmonitor 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via the maincat_id parameter.
CVE-2008-6622 1 Webbdomian 1 Post Card 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2008-2901 1 Haudenschilt 1 Family Connections Cms 2026-04-23 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated users to execute arbitrary SQL commands via the (1) address parameter to addressbook.php, the (2) getnews parameter to familynews.php, and the (3) poll_id parameter to home.php in a results action.
CVE-2009-0402 1 Gplhost 1 Domain Technologie Control 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in client/new_account.php in Domain Technologie Control (DTC) before 0.29.16 allows remote attackers to execute arbitrary SQL commands via the (1) familyname, (2) christname, (3) company_name, (4) is_company, (5) email, (6) phone, (7) fax, (8) addr1, (9) addr2, (10) addr3, (11) zipcode, (12) city, (13) state, (14) country, and (15) vat_num parameters.
CVE-2007-4956 1 Kwsphp 1 Kwsphp 2026-04-23 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.