Vulnerabilities (CVE)

Filtered by CWE-89
Total 20782 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-4634 1 Cacti 1 Cacti 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
CVE-2015-4633 1 Koha 1 Koha 2026-06-17 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.
CVE-2015-4628 1 Limesurvey 1 Limesurvey 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.
CVE-2015-4627 1 Pragyan Cms Project 1 Pragyan Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Pragyan CMS 3.0.
CVE-2015-4615 1 Easy2map 1 Easy2map-photos 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables
CVE-2015-4614 1 Easy2map Project 1 Easy2map 2026-06-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.
CVE-2015-4613 1 Developer Log Project 1 Developer Log 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the backend module in the Developer Log (devlog) extension before 2.11.4 for TYPO3 allows remote editors to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-4612 1 Faq-frequenty Asked Questions Project 1 Faq-frequently Asked Questions 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the "FAQ - Frequently Asked Questions" (js_faq) extension before 1.2.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-4611 1 Smoelenboek Project 1 Smoelenboek 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the Smoelenboek (ncgov_smoelenboek) extension before 1.0.9 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-4610 1 Store Locator Project 1 Store Locator 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-4609 1 Wt Directory Project 1 Wt Directory 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the wt_directory extension before 1.4.2 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-4592 1 Eclinicalworks 1 Population Health 2026-06-17 6.5 MEDIUM 8.8 HIGH
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.
CVE-2015-4454 2 Cacti, Fedoraproject 2 Cacti, Fedora 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
CVE-2015-4426 1 Pimcore 1 Pimcore 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/asset/grid-proxy.
CVE-2015-4348 1 Spider Contacts Project 1 Spider Contacts 2026-06-17 6.0 MEDIUM N/A
SQL injection vulnerability in the Spider Contacts module for Drupal allows remote authenticated users with the "access Spider Contacts category administration" permission to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-4342 2 Cacti, Fedoraproject 2 Cacti, Fedora 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.
CVE-2015-4233 1 Cisco 1 Unified Meetingplace 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu54037.
CVE-2015-4222 1 Cisco 1 Unified Communications Manager Im And Presence Service 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq46325.
CVE-2015-4208 1 Cisco 1 Webex Meeting Center 2026-06-17 7.5 HIGH N/A
Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.
CVE-2015-4188 1 Cisco 1 Prime Collaboration 2026-06-17 5.0 MEDIUM N/A
SQL injection vulnerability in the Manager interface in Cisco Prime Collaboration 10.5(1) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug IDs CSCuu29910, CSCuu29928, and CSCuu59104.