← Back
CWE-89

20,791 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,791)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fork Cms
1Fork Cms
Jun 17, 2026
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.
1Yejiao
1Tuzicms
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.
1Iteachyou
1Dreamer Cms
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.
1Fork Cms
1Fork Cms
Jun 17, 2026
Mar 24, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.
1Apimanager Project
1Apimanager
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.
1Money Transfer Management System Project
1Money Transfer Management System
Jun 17, 2026
Mar 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=transaction/view_details' via the 'id' parameter.
1Money Transfer Management System Project
1Money Transfer Management System
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.
1Rockwellautomation
1Factorytalk Assetcentre
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL state...Show more
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.Show less
1Rockwellautomation
1Factorytalk Assetcentre
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arb...Show more
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.Show less
1Rockwellautomation
1Factorytalk Assetcentre
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute...Show more
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.Show less
1Cmswing
1Cmswing
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.
1Mcafee
1Epolicy Orchestrator
Jun 17, 2026
Mar 23, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtaine...Show more
A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to obtain sensitive data the attacker would require administrator privileges.Show less
1Baomidou
1Mybatis Plus
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement...Show more
MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.Show less
1Softwell
1Webrun
Jun 17, 2026
Mar 22, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
1Sophos
1Unified Threat Management
Jun 17, 2026
Mar 22, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP...Show more
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.Show less
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via...Show more
Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.Show less
1Oretnom23
1Simple Subscription Website
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted...Show more
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.Show less
1Quantumcloud
1Simple Link Directory
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and auth...Show more
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL InjectionShow less
1Quantumcloud
1Infographic Maker
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authentic...Show more
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL InjectionShow less