CWE-89
20,865 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,865)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2. |
1Wedding Planner Project 1Wedding Planner Jun 17, 2026 Sep 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php. |
Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=deletecand&id=. |
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform v...Show more |
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. |
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the...Show more |
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in th...Show more |
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections |
1Zephyr One 1Zephyr Project Manager Jun 17, 2026 Sep 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated us...Show more |
1Ketchup Restaurant Reservations Project 1Ketchup Restaurant Reservations Jun 17, 2026 Sep 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL...Show more |
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf. |
Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring. |
1Zohocorp 3Manageengine Access Manager Plus Manageengine Pam360Manageengine Password Manager ProJun 17, 2026 Sep 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities. |
1School Activity Updates With Sms Notification Project 1School Activity Updates With Sms Notification Jun 17, 2026 Sep 16, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=. |
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php. |
1School Activity Updates With Sms Notification Project 1School Activity Updates With Sms Notification Jun 17, 2026 Sep 16, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=. |
1School Activity Updates With Sms Notification Project 1School Activity Updates With Sms Notification Jun 17, 2026 Sep 16, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=. |
ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface. |
1Globalnorthstar 1Northstar Club Management Jun 17, 2026 Sep 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in...Show more |