← Back
CWE-89

20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,790)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Auto Spare Parts Management Project
1Auto Spare Parts Management
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
1Cosmetics And Beauty Product Online Store Project
1Cosmetics And Beauty Product Online Store
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
1Medical Store Management System Project
1Medical Store Management System
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php.
1Simple Bakery Shop Management Project
1Simple Bakery Shop Management
Jun 17, 2026
Mar 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
1Fortinet
1Fortiwlm
Jun 17, 2026
Mar 1, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attack...Show more
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the AP monitor handlers.Show less
1Taocms
1Taocms
Jun 17, 2026
Mar 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment Update field.
1Taogogo
1Taocms
Jun 17, 2026
Mar 1, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.
1Car Driving School Management System Project
1Car Driving School Management System
Jun 17, 2026
Feb 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
1Accesspressthemes
1Ap Custom Testimonial
Jun 17, 2026
Feb 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection
1Templateinvaders
1Ti Woocommerce Wishlist
Jun 17, 2026
Feb 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/...Show more
The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacksShow less
1Asgaros
1Asgaros Forum
Jun 17, 2026
Feb 28, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQ...Show more
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injectionShow less
1Ljapps
1Wp Review Slider
Jun 17, 2026
Feb 28, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks
1Wpscan
1Wp Cloudy
Jun 17, 2026
Feb 28, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue
1Orange Form Project
1Orange Form
Jun 17, 2026
Feb 28, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page th...Show more
In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF protection, it is actually exploitable and could allow attackers to make a logged in admin delete arbitrary posts for exampleShow less
1Home Owners Collection Management System Project
1Home Owners Collection Management System
Jun 17, 2026
Feb 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.
1Veronalabs
1Wp Statistics
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers wit...Show more
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.Show less
1Veronalabs
1Wp Statistics
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows...Show more
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.Show less
1Hospital's Patient Records Management System Project
1Hospital's Patient Records Management System
Jun 17, 2026
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.
1Hospital's Patient Records Management System Project
1Hospital's Patient Records Management System
Jun 17, 2026
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.
1Veronalabs
1Wp Statistics
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allow...Show more
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.Show less