Vulnerabilities (CVE)

Filtered by CWE-89
Total 19871 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10550 1 Sequelizejs 1 Sequelize 2026-06-17 7.5 HIGH 9.8 CRITICAL
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in their own SQL statements. This affects sequelize 3.16.0 and earlier.
CVE-2016-10509 1 Opencart 1 Opencart 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.
CVE-2016-10379 1 Virtuemart 1 Virtuemart 2026-06-17 6.5 MEDIUM 7.2 HIGH
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.
CVE-2016-10378 1 E107 1 E107 2026-06-17 6.5 MEDIUM 7.2 HIGH
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
CVE-2016-10204 1 Zoneminder 1 Zoneminder 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
CVE-2016-10134 1 Zabbix 1 Zabbix 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
CVE-2016-10114 1 Awebsupport 1 Aweb Cart Watching System For Virtuemart 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the "aWeb Cart Watching System for Virtuemart" extension before 2.6.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via vectors involving categorysearch and smartSearch.
CVE-2016-10096 1 Genixcms 1 Genixcms 2026-06-17 7.5 HIGH 7.3 HIGH
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.
CVE-2016-10008 1 Dotcms 1 Dotcms 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
CVE-2016-10007 1 Dotcms 1 Dotcms 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
CVE-2016-1000271 1 Dthdevelopment 1 Dt Register 2026-06-17 7.5 HIGH 9.8 CRITICAL
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web server.
CVE-2016-1000217 1 Zotpress Project 1 Zotpress 2026-06-17 7.5 HIGH 9.8 CRITICAL
Zotpress plugin for WordPress SQLi in zp_get_account()
CVE-2016-1000125 1 Huge-it 1 Huge-it Catalog 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
CVE-2016-1000124 1 Huge-it 1 Portfolio Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CVE-2016-1000123 1 Huge-it 1 Video Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
CVE-2016-1000122 1 Huge-it 1 Slider 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2016-1000120 1 Huge-it 1 Catalog 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000119 1 Huge-it 1 Catalog 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000118 1 Huge-it 1 Slideshow 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000117 1 Huge-it 1 Slideshow 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4