← Back
CWE-89

20,825 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,825)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
May 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.
1Phome
1Empirecms
Jun 17, 2026
May 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
1Jflyfox
1Jfinal Cms
Jun 17, 2026
May 3, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
1Bluecms Project
1Bluecms
Jun 17, 2026
May 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bluecms 1.6 has a SQL injection vulnerability at cooike.
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify databas...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify dat...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify databa...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database content...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents,...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database content...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database co...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database c...Show more
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.Show less
110web
1Photo Gallery
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.
1Themehigh
1Multiple Shipping Addresses For Woocommerce
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users...Show more
The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injectionsShow less
1Documentor Project
1Documentor
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated user...Show more
The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.Show less
1Marketingheroes
1Sitesupercharger
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated user...Show more
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL InjectionsShow less
1Mingsoft
1Mcms
Jun 17, 2026
May 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.