← Back
CWE-89

20,824 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,824)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Msvod
1Msvod Cms
Jun 17, 2026
Apr 29, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database.
1Rtx Project
1Rtx
Jun 17, 2026
Apr 29, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus comple...Show more
SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Apr 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.
1Victor Cms Project
1Victor Cms
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
1Hermit Project
1Hermit
Jun 17, 2026
Apr 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id).
1Hermit Project
1Hermit
Jun 17, 2026
Apr 28, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).
1Ed01 Cms Project
1Ed01 Cms
Jun 17, 2026
Apr 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.
1Cuppacms
1Cuppacms
Jul 9, 2026
Apr 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
1Cuppacms
1Cuppacms
Jul 9, 2026
Apr 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Apr 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
13xsocializer Project
13xsocializer
Jun 17, 2026
Apr 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with a low role like a subscriber or higher.
1Donations Project
1Donations
Jun 17, 2026
Apr 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (av...Show more
The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL InjectionShow less
1Usersultra
1Users Ultra
Jun 17, 2026
Apr 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (availa...Show more
The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.Show less
1Devbunch
1Master Elements
Jun 17, 2026
Apr 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using...Show more
The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL InjectionShow less
15 Stars Rating Funnel Project
15 Stars Rating Funnel
Jun 17, 2026
Apr 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action,...Show more
The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.Show less
1Advanced Page Visit Counter Project
1Advanced Page Visit Counter
Jun 17, 2026
Apr 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading t...Show more
The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injectionShow less
1Universis
1Universis Api
Jun 17, 2026
Apr 25, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API endpoints. A remote authenticated attacker could send crafted SQL statements to a vulnerable endpoin...Show more
A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API endpoints. A remote authenticated attacker could send crafted SQL statements to a vulnerable endpoint (such as /api/students/me/messages/) to, for example, retrieve personal information or change grades.Show less
1Link Admin Project
1Link Admin
Jun 17, 2026
Apr 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().
1Jfinalcms Project
1Jfinalcms
Jun 17, 2026
Apr 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
1Pimcore
1Pimcore
Jun 17, 2026
Apr 22, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data