Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,890 CVEs tagged with CWE-894,425 Critical, 8,379 High, 6,136 Medium, 949 Low, 1 Unrated.

CVE-2014-100022

Published Jan 13, 2015

SQL injection vulnerability in question.php in the mTouch Quiz before 3.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the quiz parameter to wp-ad…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100020

Published Jan 13, 2015

SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatI…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100019

Published Jan 13, 2015

SQL injection vulnerability in the LTree converter in Pomm before 1.1.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100012

Published Jan 13, 2015

SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100011

Published Jan 13, 2015

SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10029

Published Jan 13, 2015

SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10023

Published Jan 13, 2015

Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10020

Published Jan 13, 2015

SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10017

Published Jan 13, 2015

Multiple SQL injection vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) changeSort or (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10015

Published Jan 13, 2015

SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10013

Published Jan 13, 2015

SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10004

Published Jan 13, 2015

SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100003

Published Jan 13, 2015

SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers to execute arbitrary SQL com…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2839

Published Jan 12, 2015

SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands via the s parameter in the gd-star-rati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0919

Published Jan 8, 2015

Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5853

Published Jan 8, 2015

SQL injection vulnerability in the "the_search_function" function in cardoza_ajax_search.php in the AJAX Post Search (cardoza-ajax-search) plugin before 1.3 for WordPress allows r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9528

Published Jan 6, 2015

SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9520

Published Jan 5, 2015

SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arbitrary SQL commands via the historyID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9519

Published Jan 5, 2015

SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8083

Published Jan 5, 2015

SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a searc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9464

Published Jan 3, 2015

SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-5317

Published Jan 3, 2015

Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9457

Published Jan 2, 2015

SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the id parameter to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9455

Published Jan 2, 2015

SQL injection vulnerability in showads.php in CTS Projects & Software ClassAd 3.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9450

Published Jan 2, 2015

Multiple SQL injection vulnerabilities in chart_bar.php in the frontend in Zabbix before 1.8.22, 2.0.x before 2.0.14, and 2.2.x before 2.2.8 allow remote attackers to execute arbi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 15,901-15,925 of 19,890 CVEsPage 637 of 796