← Back
CWE-89

20,781 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,781)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pimcore
1Pimcore
Jun 17, 2026
Jan 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
1Aioseo
1All In One Seo
Jun 17, 2026
Jan 17, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileg...Show more
The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).Show less
1Salonerp Project
1Salonerp
Jun 17, 2026
Jan 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be d...Show more
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
1Le Yan Dental Management System Project
1Le Yan Dental Management System
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to acquire administrator’s privilege and perf...Show more
The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to acquire administrator’s privilege and perform arbitrary operations on the system or disrupt service.Show less
1Sysaid
1Sysaid
Jun 17, 2026
Jan 11, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.
1Chshcms
1Cscms
Jun 17, 2026
Jan 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cscms v4.1 allows for SQL injection via the "page_del" function.
1Chshcms
1Cscms
Jun 17, 2026
Jan 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cscms v4.1 allows for SQL injection via the "js_del" function.
1Siemens
1Comos
Jun 17, 2026
Jan 11, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web c...Show more
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.Show less
1Useful Simple Open Source Cms Project
1Useful Simple Open Source Cms
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should r...Show more
Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer version. USOC version Pb2.4Bfx3 contains a fixed version of `admin/pages/useredit.php`.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
1Wow Company
1Wpcalc
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.
1Posimyth
1The Plus Addons For Elementor
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could lead to SQL injection
1Metagauss
1Registrationmagic
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injectio...Show more
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issueShow less
1Online Thesis Archiving System Project
1Online Thesis Archiving System
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection
3Debian
FedoraprojectWordpress
3Debian Linux
FedoraWordpress
Jun 17, 2026
Jan 6, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to b...Show more
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.Show less
3Debian
FedoraprojectWordpress
3Debian Linux
FedoraWordpress
Jun 17, 2026
Jan 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugin...Show more
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this vulnerability.Show less
1Useful Simple Open Source Cms Project
1Useful Simple Open Source Cms
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a...Show more
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site admins. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.Show less
1Useful Simple Open Source Cms Project
1Useful Simple Open Source Cms
Jun 17, 2026
Jan 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized...Show more
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.Show less
1Huawei
1Harmonyos
Jun 17, 2026
Jan 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerability may cause privacy and security issues.