← Back
CWE-89

20,865 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,865)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kayrasoft
1Kayrasoft
Jun 17, 2026
Sep 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.
1Wedding Planner Project
1Wedding Planner
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.
1Janobe
1Interview Management System
Jun 17, 2026
Sep 19, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=deletecand&id=.
1Hanssak
2Securegate
Weblink
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform v...Show more
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victim’s system.Show less
1Bpcbt
1Smartvista
Jul 9, 2026
Sep 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
1Basixonline
1Nex Forms
Jun 17, 2026
Sep 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the...Show more
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.Show less
1Cozmoslabs
1Translatepress
Jun 17, 2026
Sep 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in th...Show more
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected.Show less
1Badgeos
1Badgos
Jun 17, 2026
Sep 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
1Zephyr One
1Zephyr Project Manager
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated us...Show more
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injectionsShow less
1Ketchup Restaurant Reservations Project
1Ketchup Restaurant Reservations
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL...Show more
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacksShow less
1Bpcbt
1Smartvista
Jul 9, 2026
Sep 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.
1Moderncampus
1Omni Cms
Jun 17, 2026
Sep 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring.
1Zohocorp
3Manageengine Access Manager Plus
Manageengine Pam360Manageengine Password Manager Pro
Jun 17, 2026
Sep 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
1School Activity Updates With Sms Notification Project
1School Activity Updates With Sms Notification
Jun 17, 2026
Sep 16, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.
1Testlink
1Testlink
Jun 17, 2026
Sep 16, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
1School Activity Updates With Sms Notification Project
1School Activity Updates With Sms Notification
Jun 17, 2026
Sep 16, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.
1School Activity Updates With Sms Notification Project
1School Activity Updates With Sms Notification
Jun 17, 2026
Sep 16, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.
1Yimihome
1Ywoa
Jun 17, 2026
Sep 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.
1Globalnorthstar
1Northstar Club Management
Jun 17, 2026
Sep 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in...Show more
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the /northstar/iphone/ directory. Exploitation of the SQL injection vulnerabilities allows full access to the database which contains critical data for organization’s that make full use of the software suite.Show less