← Back
CWE-89

20,877 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,877)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webfinance Project
1Webfinance
Nov 21, 2024
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability has been found in fanzila WebFinance 0.5 and classified as critical. This vulnerability affects unknown code of the file htdocs/admin/save_Contract_Signer_Role.php. The manipulation of the argument n/v le...Show more
A vulnerability has been found in fanzila WebFinance 0.5 and classified as critical. This vulnerability affects unknown code of the file htdocs/admin/save_Contract_Signer_Role.php. The manipulation of the argument n/v leads to sql injection. The patch is identified as abad81af614a9ceef3f29ab22ca6bae517619e06. It is recommended to apply a patch to fix this issue. VDB-220054 is the identifier assigned to this vulnerability.Show less
1Pbootcms
1Pbootcms
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
1Asus
1Rt Ac68u Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.
1Native Php Cms Project
1Native Php Cms
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php file.
1Jizhicms
1Jizhicms
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.
1Jocms Project
1Jocms
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.
1Jocms Project
1Jocms
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php.
1Jocms Project
1Jocms
Jun 17, 2026
Feb 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_set_mask() function in jocms/apps/mask/mask.php.
1Jocms Project
1Jocms
Jun 17, 2026
Feb 3, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.
1Ruoyi
1Ruoyi
Jun 17, 2026
Feb 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
1Easyone
1Easyone Crm
Jun 17, 2026
Feb 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag.
1202 Ecommerce
1Administrative Mandate
Jul 9, 2026
Feb 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
1Serinf
1Fast Checkin
Jul 9, 2026
Feb 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.
1Forget Heart Message Box Project
1Forget Heart Message Box
Jun 17, 2026
Feb 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.
1Forget Heart Message Box Project
1Forget Heart Message Box
Jun 17, 2026
Feb 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php.
1Eq Project
1Eq
Jun 17, 2026
Jan 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.
1Hutool
1Hutool
Jun 17, 2026
Jan 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
1Bangresto Project
1Bangresto
Jun 17, 2026
Jan 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Bangresto 1.0 via the itemID parameter.
1Thinkingsoftware
1Efence
Jun 17, 2026
Jan 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
1Contec
1Conprosys Hmi System
Jun 17, 2026
Jan 30, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtai...Show more
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained.Show less