← Back
CWE-89

20,842 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,842)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dynamicvision
1Dynamicmarkt
Jun 17, 2026
Jun 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.
1Dynamicvision
1Dynamicmarkt
Jun 17, 2026
Jun 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.
1Dynamicvision
1Dynamicmarkt
Jun 17, 2026
Jun 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.
1Ideaco
1Idealms
Jun 17, 2026
Jun 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.
1Phplist
1Phplist
Nov 21, 2024
Jun 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in PHPList 3.2.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Subscription. The manipulation leads to sql injection. The attack may be la...Show more
A vulnerability was found in PHPList 3.2.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Subscription. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Phplist
1Phplist
Nov 21, 2024
Jun 10, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the file /lists/admin/ of the component Sending Campain. The manipulation leads to sql injection. It is p...Show more
A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the file /lists/admin/ of the component Sending Campain. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Phplist
1Phplist
Nov 21, 2024
Jun 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the component Edit Subscription. The manipulation leads to sql injection....Show more
A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the component Edit Subscription. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by S...Show more
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this vulnerability a user must be logged in.Show less
1Prison Management System Project
1Prison Management System
Jun 17, 2026
Jun 9, 2022
N/A· v4
7.2 HIGH· v3
7.5 HIGH· v2
A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unknown function of the file /admin/?page=inmates/view_inmate of the component Inmate Handler. The mani...Show more
A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unknown function of the file /admin/?page=inmates/view_inmate of the component Inmate Handler. The manipulation of the argument id with the input 1%27%20and%201=2%20union%20select%201,user(),3,4,5,6,7,8,9,0,database(),2,3,4,5,6,7,8,9,0,1,2,3,4--+ leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Prison Management System Project
1Prison Management System
Jun 17, 2026
Jun 9, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pms/admin/visits/view_visit.php of the component Visit Hand...Show more
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pms/admin/visits/view_visit.php of the component Visit Handler. The manipulation of the argument id with the input 2%27and%201=2%20union%20select%201,2,3,4,5,6,7,user(),database()--+ leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jun 9, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using t...Show more
CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.Show less
1Churchcrm
1Churchcrm
Jun 17, 2026
Jun 8, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
1Dwbooster
1Cp Image Store With Slideshow
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allow...Show more
The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query parameter before using it in a SQL statement in pages where the [codepeople-image-store] is embed, allowing unauthenticated users to perform an SQL injection attackShow less
1Realtyworkstation
1Realty Workstation
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection
1Datainterlock
1Note Press
Jun 17, 2026
Jun 8, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection
1Datainterlock
1Note Press
Jun 17, 2026
Jun 8, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection
1Datainterlock
1Note Press
Jun 17, 2026
Jun 8, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections
1Logo Slider Project
1Logo Slider
Jun 17, 2026
Jun 8, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection
1Five Minute Webshop Project
1Five Minute Webshop
Jun 17, 2026
Jun 8, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection
1Five Minute Webshop Project
1Five Minute Webshop
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection