CWE-89
20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,790)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Icegram 1Email Subscribers & Newsletters Jun 17, 2026 Mar 7, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks...Show more |
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As...Show more |
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform S...Show more |
2Codepress Wp Visitor Statistics Project2Visitor Statistics Wp Visitor StatisticsJun 17, 2026 Mar 7, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated...Show more |
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection |
The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL statement via the adrotate_request_action function available to admins, leading to a SQL injection |
The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action before using it in a SQL statement, allowing...Show more |
1Wpaffiliatefeed 1Tradetracker Store Jun 17, 2026 Mar 7, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. |
The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leadi...Show more |
3Fedoraproject PostgresqlRedhat6Enterprise Linux Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+3 moreJun 17, 2026 Mar 4, 2022 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established,...Show more |
1Victor Cms Project 1Victor Cms Jun 17, 2026 Mar 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. |
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. |
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java. |
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. |
OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database. |
OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database. |
1Bank Management System Project 1Bank Management System Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter. |
1Simple Mobile Comparison Website Project 1Simple Mobile Comparison Website Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. |
1Air Cargo Management System Project 1Air Cargo Management System Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter. |
1Simple Real Estate Portal System Project 1Simple Real Estate Portal System Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. |