← Back
CWE-89

20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,927)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jeecg
1Jeecgboot
Jun 17, 2026
Jun 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo at org.jeecg.modules.api.controller.SystemApiController.
1Jeecg
1Jeecgboot
Jun 17, 2026
Jun 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.SystemApiController.
1Agro School Management System Project
1Agro School Management System
Jun 17, 2026
Jun 18, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in code-projects Agro-School Management System 1.0. Affected by this issue is some unknown functionality of the file loaddata.php. The manipulation of the...Show more
A vulnerability, which was classified as critical, has been found in code-projects Agro-School Management System 1.0. Affected by this issue is some unknown functionality of the file loaddata.php. The manipulation of the argument subject/course leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-231806 is the identifier assigned to this vulnerability.Show less
1Minical
1Minical
Jun 17, 2026
Jun 18, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in miniCal 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /booking/show_bookings/. The manipulation of the argument search_query leads to sql inject...Show more
A vulnerability was found in miniCal 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /booking/show_bookings/. The manipulation of the argument search_query leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231803. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Jun 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. By using crafted requests, custom SQL code can be injected through the...Show more
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. By using crafted requests, custom SQL code can be injected through the REST API because of missing input validation. Regular user privileges can use used for exploitation. Editions other than Enterprise are also affected.Show less
1Jeecg
1Jeecg Boot
Jun 17, 2026
Jun 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
1Rudderstack
1Rudder Server
Jun 17, 2026
Jun 16, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to...Show more
rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue.Show less
1Ipandlanguageredirect Project
1Ipandlanguageredirect
Jun 17, 2026
Jun 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.
1Simple Customer Relationship Management Project
1Simple Customer Relationship Management
Jun 17, 2026
Jun 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
1Progress
1Moveit Transfer
Jun 17, 2026
Jun 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web applicati...Show more
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. These are fixed versions of the DLL drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3).Show less
1Thinkingsoftware
1Efence
Jun 17, 2026
Jun 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
1Forcepoint
2Email Security
Web Security
Jun 17, 2026
Jun 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL In...Show more
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.Show less
1Ai Dev
1Ailinear
Jun 17, 2026
Jun 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.
1Piwigo
1Piwigo
Jun 17, 2026
Jun 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
1Phpgurukul
1Rail Pass Management System
Jun 17, 2026
Jun 15, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request H...Show more
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The identifier VDB-231625 was assigned to this vulnerability.Show less
1Leotheme
1Leocustomajax
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.
1Webbax
1Postfinance
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.