Vulnerabilities (CVE)

Filtered by CWE-89
Total 20770 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-5648 1 Theforeman 1 Foreman 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.
CVE-2012-5590 2 Drupal, Scripthead 2 Drupal, Webmail Plus 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the Webmail Plus module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2012-5550 2 Carlos Carvalhar, Drupal 2 Time Spent, Drupal 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2012-5453 1 Atutor 1 Acontent 2026-06-16 6.5 MEDIUM N/A
SQL injection vulnerability in user/index_inline_editor_submit.php in ATutor AContent 1.2-1 allows remote authenticated users to execute arbitrary SQL commands via the field parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-5167.
CVE-2012-5367 1 Orangehrm 1 Orangehrm 2026-06-16 6.0 MEDIUM N/A
Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sortField parameter to (1) viewCustomers, (2) viewPayGrades, or (3) viewSystemUsers in symfony/web/index.php/admin/, as demonstrated using cross-site request forgery (CSRF) attacks.
CVE-2012-5350 1 Wordpress 2 Pay-with-tweet, Wordpress 2026-06-16 6.0 MEDIUM N/A
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.
CVE-2012-5348 1 Wilson Steven 1 Mangosweb Enhanced 2026-06-16 6.8 MEDIUM N/A
SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php.
CVE-2012-5342 1 Michau Enterprises Llc 1 Commonsense Cms 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) special.php, (2) article.php, or (3) cat2.php.
CVE-2012-5334 1 Preprojects 1 Pre Printing Press 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter.
CVE-2012-5333 1 Preprojects 1 Pre Printing Press 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2012-5328 2 Cartpauj, Wordpress 2 Mingle-forum, Wordpress 2026-06-16 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrary SQL commands via the (1) memberid or (2) groupid parameters in a removemember action or (3) id parameter to fs-admin/fs-admin.php, or (4) edit_forum_id parameter in an edit_save_forum action to fs-admin/wpf-edit-forum-group.php.
CVE-2012-5327 2 Cartpauj, Wordpress 2 Mingle-forum, Wordpress 2026-06-16 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2) usergroup parameter in an add_user_togroup action, or (3) add_forum_group_id parameter in an add_forum_submit action.
CVE-2012-5317 1 Bigware 1 Bigware Shop 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in main_bigware_43.php in Bigware Shop before 2.1.5 allows remote attackers to execute arbitrary SQL commands via the lastname parameter in a process action.
CVE-2012-5313 1 Snitz Communications 1 Snitz Forums 2000 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter.
CVE-2012-5312 1 Tribiq 1 Tribiq Cms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
CVE-2012-5310 2 Getshopped, Wordpress 2 Wp E-commerce, Wordpress 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2012-5300 1 Mystorexpress 1 Tienda Virtual 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in art_catalogo.php in MyStore Xpress Tienda Virtual 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2012-5297 1 Mavili Guestbook Project 1 Mavili Guestbook 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2012-5294 1 Mystorexpress 1 Tienda Virtual 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2012-5292 1 Atar2b 1 Atar2b Cms 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Atar2b CMS 4.0.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) gallery_e.php, (2) pageE.php, or (3) pageH.php.