← Back
CWE-89

20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,790)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mage People
1Event Manager And Tickets Selling For Woocommerce
Jun 17, 2026
Mar 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which...Show more
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacksShow less
1Highfivery
1Zero Spam
Jun 17, 2026
Mar 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection
110web
1Photo Gallery
Jun 17, 2026
Mar 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unaut...Show more
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injectionShow less
1Molie Instructure Canvas Linking Tool Project
1Molie Instructure Canvas Linking Tool
Jun 17, 2026
Mar 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection
1Techspawn
1Wp Email Users
Jun 17, 2026
Mar 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks.
1Moodle
1Moodle
Jun 17, 2026
Mar 11, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3...Show more
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.Show less
1Freetakserver Ui Project
1Freetakserver Ui
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.
1Softinventive
1Network Olympus
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default in...Show more
Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.Show less
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements.
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.
1Pandorafms
1Pandora Fms
Jun 17, 2026
Mar 10, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject S...Show more
Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.Show less
1Quicklert
1Quicklert
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
7.8 HIGH· v2
The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data withi...Show more
The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the login.jsp uname parameter.Show less
1Siemens
1Sinec Network Management System
Jun 17, 2026
Mar 8, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). A privileged authenticated attacker could execute arbitrary commands in the local database by sending specially...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). A privileged authenticated attacker could execute arbitrary commands in the local database by sending specially crafted requests to the webserver of the affected application.Show less
1Salesagility
1Suitecrm
Jun 17, 2026
Mar 7, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.