CWE-89
20,791 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,791)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microfinance Management System Project 1Microfinance Management System Jun 17, 2026 Mar 29, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' a...Show more |
1Microfinance Management System Project 1Microfinance Management System Jun 17, 2026 Mar 29, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/pass...Show more |
1One Church Management System Project 1One Church Management System Jun 17, 2026 Mar 29, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads...Show more |
1College Website Management System Project 1College Website Management System Jun 17, 2026 Mar 29, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id wi...Show more |
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based bl...Show more |
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. |
1Speakout! Email Petitions Project 1Speakout! Email Petitions Jun 17, 2026 Mar 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection explo...Show more |
1Limit Login Attempts Project 1Limit Login Attempts Jun 17, 2026 Mar 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQ...Show more |
1Title Experiments Free Project 1Title Experiments Free Jun 17, 2026 Mar 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to a...Show more |
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection,...Show more |
1Stopbadbots 1Block And Stop Bad Bots Jun 17, 2026 Mar 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue |
1Dpl 1Sync Woocommerce Product Feed To Google Shopping Jun 17, 2026 Mar 28, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability i...Show more |
The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection. |
TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php. |
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated. |
1Xiaohuanxiong Project 1Xiaohuanxiong Jun 17, 2026 Mar 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php. |
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. |
Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Mar 25, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default. |
An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form. |