Vulnerabilities (CVE)

Filtered by CWE-89
Total 20773 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-6719 1 Sharebar Project 1 Sharebar 2026-06-16 7.5 HIGH 9.8 CRITICAL
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
CVE-2012-6654 1 Zpanelcp 1 Zpanel 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) resetkey or (2) inConfEmail parameter to index.php, a different vulnerability than CVE-2012-5685.
CVE-2012-6643 1 Clip-bucket 1 Clipbucket 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the time parameter to (1) videos.php or (2) channels.php. NOTE: some of these details are obtained from third party information.
CVE-2012-6626 1 Brian Cabunac 1 Browser To Email Phone Message System 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
CVE-2012-6625 1 Vasthtml 1 Forumpress 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action.
CVE-2012-6588 1 Myrephp 1 Myre Business Directory 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2012-6586 1 Myrephp 1 Myre Vacation Rental 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the (1) garage1 or (2) bathrooms1 parameter to vacation/1_mobile/search.php, or (3) unspecified input to vacation/widgate/request_more_information.php.
CVE-2012-6584 1 Myrephp 1 Myre Realty Manager 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands via the bathrooms1 parameter to (1) demo2/search.php or (2) search.php.
CVE-2012-6577 2 Typo3, Typoheads 2 Typo3, Formhandler 2026-06-16 6.0 MEDIUM N/A
SQL injection vulnerability in the Formhandler extension before 1.4.1 for TYPO3 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via unspecified vectors.
CVE-2012-6529 1 Marinet 1 Marinet Cms 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) galleryphoto.php or (2) gallery.php; or the roomid parameter to (3) room.php or (4) room2.php.
CVE-2012-6526 1 Vastal 1 Freelance Zone 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in show_code.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the code_id parameter.
CVE-2012-6525 1 Phpbridges Dev Team 1 Phpbridges 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in members.php in PHPBridges allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2012-6524 1 Powie 1 Pgb 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in kommentar.php in pGB 2.12 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2012-6520 1 Wikidforum 1 Wikidforum 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.
CVE-2012-6519 1 Diy-cms 1 Diy-cms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter to mod.php.
CVE-2012-6516 1 Shawn Bradley 1 Php Ticket System 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in PHP Ticket System Beta 1 allows remote attackers to execute arbitrary SQL commands via the q parameter to index.php.
CVE-2012-6507 1 Jason Sexauer 1 Churchcms 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in admin.php in ChurchCMS 0.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameters in a login action.
CVE-2012-6504 1 Shawn Bradley 1 Php Volunteer Management 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2012-6497 1 Rubyonrails 1 Rails 2026-06-16 5.0 MEDIUM N/A
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.
CVE-2012-6496 1 Rubyonrails 2 Rails, Ruby On Rails 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.