← Back
CWE-89

20,873 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,873)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Limesurvey
1Limesurvey
Jun 17, 2026
Nov 15, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
1Badgermeter
1Moni\
Jun 17, 2026
Nov 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL injection. This may result in loss of confidentiality, loss of integrity and DoS.
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Nov 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the...Show more
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.Show less
1Liferay
3Digital Experience Platform
DxpLiferay Portal
Jul 9, 2026
Nov 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticate...Show more
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.Show less
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Nov 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a Portle...Show more
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.Show less
1Wowonder
1Wowonder
Jun 17, 2026
Nov 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.
1Wowonder
1Wowonder
Jun 17, 2026
Nov 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs.
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Nov 14, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type=php.
1Zohocorp
3Manageengine Access Manager Plus
Manageengine Pam360Manageengine Password Manager Pro
Jun 17, 2026
Nov 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
1Zohocorp
3Manageengine Access Manager Plus
Manageengine Pam360Manageengine Password Manager Pro
Jun 17, 2026
Nov 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
1Hhims Project
1Hhims
Jun 17, 2026
Nov 11, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical has been found in tsruban HHIMS 2.1. Affected is an unknown function of the component Patient Portrait Handler. The manipulation of the argument PID leads to sql injection. It is po...Show more
A vulnerability classified as critical has been found in tsruban HHIMS 2.1. Affected is an unknown function of the component Patient Portrait Handler. The manipulation of the argument PID leads to sql injection. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. VDB-213462 is the identifier assigned to this vulnerability.Show less
1Crm42 Project
1Crm42
Jun 17, 2026
Nov 11, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in tholum crm42. It has been rated as critical. This issue affects some unknown processing of the file crm42\class\class.user.php of the component Login. The manipulation of the argument user_na...Show more
A vulnerability was found in tholum crm42. It has been rated as critical. This issue affects some unknown processing of the file crm42\class\class.user.php of the component Login. The manipulation of the argument user_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213461 was assigned to this vulnerability.Show less
1Eolink
1Goku Lite
Jun 17, 2026
Nov 11, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical was found in eolinker goku_lite. This vulnerability affects unknown code of the file /plugin/getList. The manipulation of the argument route/keyword leads to sql injection. The atta...Show more
A vulnerability classified as critical was found in eolinker goku_lite. This vulnerability affects unknown code of the file /plugin/getList. The manipulation of the argument route/keyword leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-213454 is the identifier assigned to this vulnerability.Show less
1Eolink
1Goku Lite
Jun 17, 2026
Nov 11, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical has been found in eolinker goku_lite. This affects an unknown part of the file /balance/service/list. The manipulation of the argument route/keyword leads to sql injection. It is po...Show more
A vulnerability classified as critical has been found in eolinker goku_lite. This affects an unknown part of the file /balance/service/list. The manipulation of the argument route/keyword leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213453 was assigned to this vulnerability.Show less
1Archesproject
1Arches
Jun 17, 2026
Nov 11, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Arches is a web platform for creating, managing, & visualizing geospatial data. Versions prior to 6.1.2, 6.2.1, and 7.1.2 are vulnerable to SQL Injection. With a carefully crafted web request, it's possible to execute ce...Show more
Arches is a web platform for creating, managing, & visualizing geospatial data. Versions prior to 6.1.2, 6.2.1, and 7.1.2 are vulnerable to SQL Injection. With a carefully crafted web request, it's possible to execute certain unwanted sql statements against the database. This issue is fixed in version 7.12, 6.2.1, and 6.1.2. Users are recommended to upgrade as soon as possible. There are no workarounds.Show less
1Lineagrafica
1Eu Cookie Law Gdpr
Jun 17, 2026
Nov 10, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 9, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the categoriesId parameter at /php_action/fetchSelectedCategories.php.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editfood.php.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editclient.php.