CWE-89
20,866 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,866)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which has been given permission to run exports to execute arbitrary SQL stat...Show more |
1Cleantalk 1Spam Protection, Antispam, Firewall Jun 17, 2026 Oct 25, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such...Show more |
The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin |
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authe...Show more |
1Best Student Result Management System Project 1Best Student Result Management System Jun 17, 2026 Oct 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=. |
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function. |
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function. |
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable. |
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function. |
1Open Source Sacco Management System Project 1Open Source Sacco Management System Jun 17, 2026 Oct 18, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Oct 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument business leads...Show more |
1Oretnom23 1Cashier Queuing System Jun 17, 2026 Oct 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical was found in SourceCodester Cashier Queuing System 1.0. This vulnerability affects unknown code of the file /queuing/login.php of the component Login Page. The manipulation of the a...Show more |
1Changingtec 1Rava Certificate Validation System Jun 17, 2026 Oct 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database. |
1Rockwellautomation 1Factorytalk Vantagepoint Jun 17, 2026 Oct 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL s...Show more |
1Open Source Sacco Management System Project 1Open Source Sacco Management System Jun 17, 2026 Oct 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php. |
1Merchandise Online Store Project 1Merchandise Online Store Jun 17, 2026 Oct 17, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account. |
1Billing System Project 1Billing System Jun 17, 2026 Oct 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. |
1Smackcoders 1Import All Pages, Post Types, Products, Orders, And Users As Xml & Csv Jun 17, 2026 Oct 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as...Show more |
The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users |
1Online Tours & Travels Management System Project 1Online Tours & Travels Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /user/update_booking.php. |