CWE-89
20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,790)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cybonet 1Pineapp Mail Secure Jun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichme...Show more |
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracker Puncher plugin in versions of anuko tim...Show more |
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter. |
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter. |
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php. |
5Cyrusimap DebianFedoraproject+2 more8Active Iq Unified Manager Communications Cloud Native Core ConsoleCommunications Cloud Native Core Network Function Cloud Native Environment+5 moreJun 17, 2026 Feb 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. |
1Phpuploader Project 1Phpuploader Jun 17, 2026 Feb 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the information in the database via unspecified vectors. |
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters i...Show more |
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php. |
1Deliciousbrains 1Database Backup Jun 17, 2026 Feb 21, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue |
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users t...Show more |
The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using it in a SQL statement, leading to a SQL injection vulnerability exploitable by high privilege users |
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected...Show more |
1Baicloud Cms Project 1Baicloud Cms Jun 17, 2026 Feb 19, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Feb 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters. |
1Airspan 5A5x Firmware C5c FirmwareC5x Firmware+2 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input, which may allow an attacker to perfo...Show more |
1Expressionengine 1Expressionengine Jun 17, 2026 Feb 18, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack. |
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection. |
A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do |