← Back
CWE-89

20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,790)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Icegram
1Email Subscribers & Newsletters
Jun 17, 2026
Mar 7, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks...Show more
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.Show less
1A3rev
1Page View Count
Jun 17, 2026
Mar 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As...Show more
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacksShow less
1Metagauss
1Registrationmagic
Jun 17, 2026
Mar 7, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform S...Show more
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacksShow less
2Codepress
Wp Visitor Statistics Project
2Visitor Statistics
Wp Visitor Statistics
Jun 17, 2026
Mar 7, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated...Show more
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injectionShow less
1Wpdeveloper
1Notificationx
Jun 17, 2026
Mar 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection
1Adrotate Project
1Adrotate
Jun 17, 2026
Mar 7, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection
1Conversios
1Conversios
Jun 17, 2026
Mar 7, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing...Show more
The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing any authenticated user to perform SQL injection attacks.Show less
1Wpaffiliatefeed
1Tradetracker Store
Jun 17, 2026
Mar 7, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
1Hotscot
1Contact Form
Jun 17, 2026
Mar 7, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leadi...Show more
The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection.Show less
3Fedoraproject
PostgresqlRedhat
6Enterprise Linux
Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+3 more
Jun 17, 2026
Mar 4, 2022
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established,...Show more
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.Show less
1Victor Cms Project
1Victor Cms
Jun 17, 2026
Mar 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
1Mingsoft
1Mcms
Jun 17, 2026
Mar 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
1Mingsoft
1Mcms
Jun 17, 2026
Mar 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
1Mingsoft
1Mcms
Jun 17, 2026
Mar 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
1Os4ed
1Opensis
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
1Os4ed
1Opensis
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.
1Bank Management System Project
1Bank Management System
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.
1Simple Mobile Comparison Website Project
1Simple Mobile Comparison Website
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
1Air Cargo Management System Project
1Air Cargo Management System
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.
1Simple Real Estate Portal System Project
1Simple Real Estate Portal System
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.