← Back
CWE-89

20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,790)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Diskstation Manager
Jun 17, 2026
Feb 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers t...Show more
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.Show less
1Synology
1Diskstation Manager
Jun 17, 2026
Feb 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inj...Show more
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.Show less
1Synology
1Diskstation Manager
Jun 17, 2026
Feb 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inj...Show more
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors.Show less
1Emlog
1Emlog
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
1[gwa] Autoresponder Project
1[gwa] Autoresponder
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed.
1Voipmonitor
1Voipmonitor
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
1Projectworlds
1Online Movie Ticket Booking System
Jun 17, 2026
Feb 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive informati...Show more
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.Show less
1Unifiedoffice
1Total Connect Now
Jun 17, 2026
Feb 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.
1Victor Cms Project
1Victor Cms
Jun 17, 2026
Feb 3, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.
1Printerlogic
1Web Stack
Jul 9, 2026
Feb 2, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.
1Capsule8
1Capsule8
Jun 17, 2026
Feb 2, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.
1Thedigitalcraft
1Atomcms
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
1Elitecms
1Elite Cms
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
1Elitecms
1Elite Cms
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
1Elitecms
1Elite Cms
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.
1Elitecms
1Elite Cms
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.
1Wickedplugins
1Wicked Folders
Jun 17, 2026
Feb 1, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated...Show more
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injectionShow less
1Getperfectsurvey
1Perfect Survey
Jun 17, 2026
Feb 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQ...Show more
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.Show less