CWE-89
20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,790)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Synology 1Diskstation Manager Jun 17, 2026 Feb 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers t...Show more |
1Synology 1Diskstation Manager Jun 17, 2026 Feb 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inj...Show more |
1Synology 1Diskstation Manager Jun 17, 2026 Feb 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inj...Show more |
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid(). |
1[gwa] Autoresponder Project 1[gwa] Autoresponder Jun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed. |
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. |
1Projectworlds 1Online Movie Ticket Booking System Jun 17, 2026 Feb 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive informati...Show more |
1Unifiedoffice 1Total Connect Now Jun 17, 2026 Feb 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter. |
1Victor Cms Project 1Victor Cms Jun 17, 2026 Feb 3, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter. |
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records. |
An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1. |
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. |
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. |
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. |
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. |
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. |
1Simple Client Management System Project 1Simple Client Management System Jun 17, 2026 Feb 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php. |
1Simple Client Management System Project 1Simple Client Management System Jun 17, 2026 Feb 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php. |
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated...Show more |
1Getperfectsurvey 1Perfect Survey Jun 17, 2026 Feb 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQ...Show more |