← Back
CWE-89

20,791 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,791)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microfinance Management System Project
1Microfinance Management System
Jun 17, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' a...Show more
A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc leads to sql injection in multiple files. It is possible to launch the attack remotely.Show less
1Microfinance Management System Project
1Microfinance Management System
Jun 17, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/pass...Show more
A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/password with the input '||1=1# leads to sql injection. The attack may be initiated remotely.Show less
1One Church Management System Project
1One Church Management System
Jun 17, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads...Show more
A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads to sql injection. The attack can be initiated remotely.Show less
1College Website Management System Project
1College Website Management System
Jun 17, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id wi...Show more
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. It is possible to launch the attack remotely and without authentication.Show less
1Shopware
1B2b Suite
Jun 17, 2026
Mar 29, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based bl...Show more
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.Show less
1Kreado
1Kreasfero
Jun 17, 2026
Mar 29, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.
1Speakout! Email Petitions Project
1Speakout! Email Petitions
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection explo...Show more
The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated usersShow less
1Limit Login Attempts Project
1Limit Login Attempts
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQ...Show more
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL InjectionsShow less
1Title Experiments Free Project
1Title Experiments Free
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to a...Show more
The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injectionShow less
1Sygnoos
1Popup Builder
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection,...Show more
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious linkShow less
1Stopbadbots
1Block And Stop Bad Bots
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue
1Dpl
1Sync Woocommerce Product Feed To Google Shopping
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability i...Show more
The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboardShow less
1Wow Company
1Wow Countdowns
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.
1Tuzicms
1Tuzicms
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.
1Glpi Project
1Glpi
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.
1Xiaohuanxiong Project
1Xiaohuanxiong
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.
1Impresscms
1Impresscms
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
1Open Falcon
1Falcon Plus
Jun 17, 2026
Mar 27, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go.
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
1Yeswiki
1Yeswiki
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form.