← Back
CWE-89

20,778 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,778)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Enrollment Management System Project
1Online Enrollment Management System
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execut...Show more
Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter.Show less
1Prestashop
1Prestashop
Jun 17, 2026
Dec 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed...Show more
PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed in version 1.7.8.2.Show less
1Ivanti
1Avalanche
Jun 17, 2026
Dec 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
1Esri
1Arcgis Server
Jun 17, 2026
Dec 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via...Show more
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.Show less
1B2evolution
1B2evolution Cms
Jun 17, 2026
Dec 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
1Piwigo
1Piwigo
Jun 17, 2026
Dec 6, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.
1Roundupwp
1Registrations For The Events Calendar
Jun 17, 2026
Dec 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) b...Show more
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.Show less
1Ays Pro
1Secure Copy Content Protection And Content Locking
Jun 17, 2026
Dec 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authentica...Show more
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.Show less
1Wpdataaccess
1Wp Data Access
Jun 17, 2026
Dec 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion
1Kaseya
1Unitrends Backup
Jun 17, 2026
Dec 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres...Show more
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible, leading to full access to the postgres user account.Show less
1Chamilo
1Chamilo Lms
Jun 17, 2026
Dec 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
1Yejiao
1Tuzicms
Jun 17, 2026
Dec 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.php.
1Yejiao
1Tuzicms
Jun 17, 2026
Dec 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php.
1Yejiao
1Tuzicms
Jun 17, 2026
Dec 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php.
1Taogogo
1Taocms
Jun 17, 2026
Dec 2, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article.
1Taogogo
1Taocms
Jun 17, 2026
Dec 2, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search.
1Broadcom
1Ca Network Flow Analysis
Jun 17, 2026
Dec 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due to insufficient input validation, that could potentially allow an authenticated user to access sensi...Show more
CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due to insufficient input validation, that could potentially allow an authenticated user to access sensitive data.Show less
1Shopex
1Ecshop
Jun 17, 2026
Dec 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.
1Pixelite
1Events Manager
Jun 17, 2026
Dec 1, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
1Phpgurukul
1Employee Record Management System
Jun 17, 2026
Dec 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.