CWE-89
20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,790)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mage People 1Event Manager And Tickets Selling For Woocommerce Jun 17, 2026 Mar 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which...Show more |
The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection |
The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unaut...Show more |
1Molie Instructure Canvas Linking Tool Project 1Molie Instructure Canvas Linking Tool Jun 17, 2026 Mar 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection |
The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks. |
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3...Show more |
1Freetakserver Ui Project 1Freetakserver Ui Jun 17, 2026 Mar 11, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser. |
1Softinventive 1Network Olympus Jun 17, 2026 Mar 10, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default in...Show more |
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. |
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. |
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. |
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. |
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. |
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. |
Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements. |
Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements. |
Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject S...Show more |
The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data withi...Show more |
1Siemens 1Sinec Network Management System Jun 17, 2026 Mar 8, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). A privileged authenticated attacker could execute arbitrary commands in the local database by sending specially...Show more |
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5. |