CWE-89
20,791 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,791)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1. |
TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php. |
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter. |
SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1. |
1Apimanager Project 1Apimanager Jun 17, 2026 Mar 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8. |
1Money Transfer Management System Project 1Money Transfer Management System Jun 17, 2026 Mar 23, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=transaction/view_details' via the 'id' parameter. |
1Money Transfer Management System Project 1Money Transfer Management System Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter. |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL state...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arb...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute...Show more |
CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule. |
1Mcafee 1Epolicy Orchestrator Jun 17, 2026 Mar 23, 2022 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtaine...Show more |
MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement...Show more |
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. |
1Sophos 1Unified Threat Management Jun 17, 2026 Mar 22, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710. |
1Simple Client Management System Project 1Simple Client Management System Jun 17, 2026 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP...Show more |
1Simple Client Management System Project 1Simple Client Management System Jun 17, 2026 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via...Show more |
1Oretnom23 1Simple Subscription Website Jun 17, 2026 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted...Show more |
1Quantumcloud 1Simple Link Directory Jun 17, 2026 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and auth...Show more |
1Quantumcloud 1Infographic Maker Jun 17, 2026 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authentic...Show more |