← Back
CWE-89

20,832 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,832)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wp Video Gallery Free Project
1Wp Video Gallery Free
Jun 17, 2026
May 9, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
1Badgeos
1Badgeos
Jun 17, 2026
May 9, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
1Ubigeo De Peru Para Woocommerce Project
1Ubigeo De Peru Para Woocommerce
Jun 17, 2026
May 9, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthe...Show more
The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL InjectionsShow less
1Mapsvg
1Mapsvg
Jun 17, 2026
May 9, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.
1Broadcom
1Sannav
Jun 17, 2026
May 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.
1Piwigo
1Piwigo
Jun 17, 2026
May 6, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
1Piwigo
1Piwigo
Jun 17, 2026
May 6, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
1Piwigo
1Piwigo
Jun 17, 2026
May 6, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
1Piwigo
1Piwigo
Jun 17, 2026
May 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
1Piwigo
1Piwigo
Jun 17, 2026
May 6, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
1Bladex
1Springblade
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
1Medical Hub Directory Site Project
1Medical Hub Directory Site
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.
1Covid 19 Directory On Vaccination System Project
1Covid 19 Directory On Vaccination System
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.
1Event Management System Project
1Event Management System
Jun 17, 2026
May 5, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
1College Management System Project
1College Management System
Jun 17, 2026
May 5, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
1Mingyuefusu Project
1Mingyuefusu
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.
1Librehealth
1Librehealth Ehr
Jun 17, 2026
May 5, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.
3Debian
NetappOpenldap
8Debian Linux
H300s FirmwareH410c Firmware+5 more
Jun 17, 2026
May 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search ope...Show more
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.Show less
1Enhancesoft
1Osticket
Jun 17, 2026
May 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.