Vulnerabilities (CVE)

Filtered by CWE-89
Total 15274 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-2090 1 Sympies 1 Wordpress Survey And Poll 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.
CVE-2015-5668 1 Techno Project Japan 1 Enisys Gw 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2014-4736 1 Blogengine 1 E2 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.
CVE-2016-1000124 1 Huge-it 1 Portfolio Gallery 2025-04-12 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CVE-2014-2339 1 Sir 1 Gnuboard 2025-04-12 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter.
CVE-2015-1392 1 Arubanetworks 1 Clearpass Policy Manager 2025-04-12 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrary SQL commands via unspecified vectors.
CVE-2014-9097 1 Apptha 1 Contus Video Gallery 2025-04-12 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) remote attackers to execute arbitrary SQL commands via the vid parameter in a myextract action to wp-admin/admin-ajax.php or (2) remote authenticated users to execute arbitrary SQL commands via the playlistId parameter in the newplaylist page or (3) videoId parameter in a newvideo page to wp-admin/admin.php.
CVE-2013-6311 1 Ibm 1 Marketing Platform 2025-04-12 6.5 MEDIUM N/A
SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2013-3478 1 Apptha 1 Video Gallery Plugin 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the playid parameter to index.php.
CVE-2016-8564 1 Siemens 1 Automation License Manager 2025-04-12 6.4 MEDIUM 6.5 MEDIUM
SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to execute arbitrary SQL commands via crafted traffic to TCP port 4410.
CVE-2011-5272 1 Gplhost 1 Domain Technologie Control 2025-04-12 6.5 MEDIUM N/A
SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtcadmin/logPushlet.php. NOTE: this issue was originally part of CVE-2011-3197, but that ID was SPLIT due to different researchers.
CVE-2015-6915 1 Montala 1 Resourcespace 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the "user" cookie to plugins/feedback/pages/feedback.php.
CVE-2012-5865 1 Achievo 1 Achievo 2025-04-12 6.5 MEDIUM N/A
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid parameter in a stats action.
CVE-2015-6009 1 Refbase 1 Refbase 2025-04-12 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.
CVE-2015-4628 1 Limesurvey 1 Limesurvey 2025-04-12 6.5 MEDIUM N/A
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.
CVE-2014-3055 1 Ibm 2 Websphere Portal, Websphere Portal Unified Task List Portlet 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in the Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-1000115 1 Huge-it 1 Portfolio Gallery Manager 2025-04-12 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-8903 1 Dotcms 1 Dotcms 2025-04-12 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
CVE-2014-4852 1 Thedigitalcraft 1 Atomcms 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2015-6516 1 Cygnux 1 Syspass 2025-04-12 6.5 MEDIUM N/A
SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitrary SQL commands via the search parameter to ajax/ajax_search.php.