Vulnerabilities (CVE)

Filtered by CWE-89
Total 20783 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10008 1 Dotcms 1 Dotcms 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
CVE-2016-10007 1 Dotcms 1 Dotcms 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
CVE-2016-1000271 1 Dthdevelopment 1 Dt Register 2026-06-17 7.5 HIGH 9.8 CRITICAL
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web server.
CVE-2016-1000217 1 Zotpress Project 1 Zotpress 2026-06-17 7.5 HIGH 9.8 CRITICAL
Zotpress plugin for WordPress SQLi in zp_get_account()
CVE-2016-1000125 1 Huge-it 1 Huge-it Catalog 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
CVE-2016-1000124 1 Huge-it 1 Portfolio Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CVE-2016-1000123 1 Huge-it 1 Video Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
CVE-2016-1000122 1 Huge-it 1 Slider 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2016-1000120 1 Huge-it 1 Catalog 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000119 1 Huge-it 1 Catalog 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000118 1 Huge-it 1 Slideshow 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000117 1 Huge-it 1 Slideshow 2026-06-17 6.5 MEDIUM 7.2 HIGH
XSS & SQLi in HugeIT slideshow v1.0.4
CVE-2016-1000116 1 Huge-it 1 Portfolio Gallery Manager 2026-06-17 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-1000115 1 Huge-it 1 Portfolio Gallery Manager 2026-06-17 6.5 MEDIUM 7.2 HIGH
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVE-2016-1000113 1 Huge-it 1 Gallery 2026-06-17 7.5 HIGH 9.8 CRITICAL
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
CVE-2016-1000000 1 Progress 1 Whatsup Gold 2026-06-17 6.5 MEDIUM 8.8 HIGH
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
CVE-2016-0769 1 Elfden 1 Eshop Plugin 2026-06-17 6.5 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.
CVE-2016-0710 1 Apache 1 Jetspeed 2026-06-17 7.5 HIGH 8.8 HIGH
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.
CVE-2016-0249 1 Ibm 1 Security Guardium 2026-06-17 7.5 HIGH 8.6 HIGH
SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-0233 1 Ibm 1 Marketing Platform 2026-06-17 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.