Vulnerabilities (CVE)

Filtered by CWE-89
Total 19859 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-7714 1 Realtyna 1 Realtyna Property Listing 2026-06-17 6.5 MEDIUM 7.2 HIGH
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting, or (9) pwizard parameter to administrator/index.php.
CVE-2015-7695 2 Debian, Zend 2 Debian Linux, Zend Framework 2026-06-17 7.5 HIGH 9.8 CRITICAL
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
CVE-2015-7682 1 Genetechsolutions 1 Pie Register 2026-06-17 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.
CVE-2015-7670 1 Support Ticket System Project 1 Support Ticket System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) id parameter.
CVE-2015-7569 1 Yeager 1 Yeager Cms 2026-06-17 7.5 HIGH 8.8 HIGH
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.
CVE-2015-7568 1 Yeager 1 Yeager Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.
CVE-2015-7567 1 Yeager 1 Yeager Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter.
CVE-2015-7564 1 Teampass 1 Teampass 2026-06-17 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.
CVE-2015-7517 1 Labwebdesigns 1 Double Opt-in For Download 2026-06-17 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.
CVE-2015-7448 1 Ibm 13 Change And Configuration Management Database, Maximo Asset Management, Maximo Asset Management Essentials and 10 more 2026-06-17 6.5 MEDIUM 5.4 MEDIUM
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-7390 1 Testlink 1 Testlink 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.
CVE-2015-7387 1 Zohocorp 1 Manageengine Eventlog Analyzer 2026-06-17 7.5 HIGH N/A
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do, as demonstrated by "SELECT 1;INSERT INTO." Fixed in Build 11200.
CVE-2015-7382 1 Refbase 1 Refbase 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary SQL commands via the defaultCharacterSet parameter, a different issue than CVE-2015-6009.
CVE-2015-7346 1 Zcms Project 1 Zcms 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in ZCMS 1.1.
CVE-2015-7342 1 Joobi 1 Jnews 2026-06-17 6.5 MEDIUM 7.2 HIGH
JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.
CVE-2015-7340 1 Gwesystems 1 Jevents 2026-06-17 6.5 MEDIUM 7.2 HIGH
JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.
CVE-2015-7338 1 Acyba 1 Acymailing 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.
CVE-2015-7319 1 Codepeople 1 Appointment Booking Calendar 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.
CVE-2015-7299 1 Nintex 3 K2 Blackpearl, K2 For Sharepoint, K2 Smartforms 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.
CVE-2015-7297 1 Joomla 1 Joomla\! 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.