← Back
CWE-89

20,877 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,877)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sscms
1Siteserver Cms
Jun 17, 2026
Jan 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
1Phpmyadmin
1Phpmyadmin
Jul 9, 2026
Jan 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
1Centreon
1Centreon
Jun 17, 2026
Jan 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests...Show more
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18304.Show less
1Amano
1Xoffice
Jun 17, 2026
Jan 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.
1Izybat
1Orange Casiers
Jun 17, 2026
Jan 23, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.
1Wp Topbar Project
1Wp Topbar
Jun 17, 2026
Jan 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Auth. SQL Injection (SQLi) vulnerability in WP-TopBar <= 5.36 versions.
1Veronalabs
1Wp Statistics
Jun 17, 2026
Jan 23, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage...Show more
The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.Show less
1Idehweb
1Login With Phone Number
Jun 17, 2026
Jan 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.
1Ays Pro
1Survey Maker
Jun 17, 2026
Jan 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.
1Remoteclinic
1Remote Clinic
Jun 17, 2026
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parameter to /medicines/profile.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor par...Show more
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.Show less
2Online Food Ordering System Project
Oretnom23
2Online Food Ordering System
Online Food Ordering System
Jun 17, 2026
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.
1Inxedu
1Inxedu
Jun 17, 2026
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
1Sandhillsdev
1Easy Digital Downloads
Jun 17, 2026
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
1Strangerstudios
1Paid Memberships Pro
Jun 17, 2026
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.
1Mangboard
1Mangboard Wp
Jun 17, 2026
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the...Show more
SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.Show less
1Cisco
1Unified Communications Manager
Jun 17, 2026
Jan 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated...Show more
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface inadequately validates user input. An attacker could exploit this vulnerability by authenticating to the application as a low-privileged user and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to read or modify any data on the underlying database or elevate their privileges.Show less
1Nexusphp
1Nexusphp
Jun 17, 2026
Jan 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the...Show more
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.Show less
1Easycorp
1Zentao
Jun 17, 2026
Jan 19, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
1Seltmann Webdesign
1Content Management System
Jun 17, 2026
Jan 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.