CWE-89
20,778 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,778)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wclovers 1Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible Jun 17, 2026 Dec 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL st...Show more |
1Ni Woocommerce Custom Order Status Project 1Ni Woocommerce Custom Order Status Jun 17, 2026 Dec 21, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter...Show more |
2Codepress Wp Visitor Statistics (real Time Traffic) Project2Visitor Statistics Wp Visitor Statistics (real Time Traffic)Jun 17, 2026 Dec 21, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with...Show more |
JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query. |
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information...Show more |
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date. |
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx. |
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query. |
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /...Show more |
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by users with "member" privilege. Users are adv...Show more |
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php. |
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse an...Show more |
1Online Pre Owned/used Car Showroom Management System Project 1Online Pre Owned/used Car Showroom Management System Jun 17, 2026 Dec 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allow...Show more |
1Oretnom23 1Online Magazine Management System Jun 17, 2026 Dec 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to...Show more |
1Microsoft 1Defender For Iot Jun 17, 2026 Dec 15, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Microsoft Defender for IoT Remote Code Execution Vulnerability |
1Microsoft 1Defender For Iot Jun 17, 2026 Dec 15, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Microsoft Defender for IoT Remote Code Execution Vulnerability |
Microsoft Defender for IoT Remote Code Execution Vulnerability |
A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php. |
OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to r...Show more |
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted da...Show more |