CWE-89
20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,790)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Auto Spare Parts Management Project 1Auto Spare Parts Management Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. |
1Cosmetics And Beauty Product Online Store Project 1Cosmetics And Beauty Product Online Store Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. |
1Medical Store Management System Project 1Medical Store Management System Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php. |
1Simple Bakery Shop Management Project 1Simple Bakery Shop Management Jun 17, 2026 Mar 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attack...Show more |
An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment Update field. |
There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit. |
1Car Driving School Management System Project 1Car Driving School Management System Jun 17, 2026 Feb 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access. |
1Accesspressthemes 1Ap Custom Testimonial Jun 17, 2026 Feb 28, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection |
1Templateinvaders 1Ti Woocommerce Wishlist Jun 17, 2026 Feb 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/...Show more |
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQ...Show more |
The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks |
The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue |
1Orange Form Project 1Orange Form Jun 17, 2026 Feb 28, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page th...Show more |
1Home Owners Collection Management System Project 1Home Owners Collection Management System Jun 17, 2026 Feb 26, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php. |
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers wit...Show more |
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows...Show more |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php. |
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allow...Show more |