CWE-89
20,832 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,832)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wp Video Gallery Free Project 1Wp Video Gallery Free Jun 17, 2026 May 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users |
The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users |
1Ubigeo De Peru Para Woocommerce Project 1Ubigeo De Peru Para Woocommerce Jun 17, 2026 May 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthe...Show more |
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users. |
In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands. |
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager. |
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm. |
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm. |
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. |
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 May 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. |
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. |
1Medical Hub Directory Site Project 1Medical Hub Directory Site Jun 17, 2026 May 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. |
1Covid 19 Directory On Vaccination System Project 1Covid 19 Directory On Vaccination System Jun 17, 2026 May 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. |
1Event Management System Project 1Event Management System Jun 17, 2026 May 5, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. |
1College Management System Project 1College Management System Jun 17, 2026 May 5, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. |
1Mingyuefusu Project 1Mingyuefusu Jun 17, 2026 May 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. |
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection. |
3Debian NetappOpenldap8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 May 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search ope...Show more |
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality. |