CWE-89
20,778 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,778)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Enrollment Management System Project 1Online Enrollment Management System Jun 17, 2026 Dec 7, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execut...Show more |
PrestaShop is an Open Source e-commerce web application. Versions of PrestaShop prior to 1.7.8.2 are vulnerable to blind SQL injection using search filters with `orderBy` and `sortOrder` parameters. The problem is fixed...Show more |
A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. |
A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via...Show more |
1B2evolution 1B2evolution Cms Jun 17, 2026 Dec 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input. |
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php. |
1Roundupwp 1Registrations For The Events Calendar Jun 17, 2026 Dec 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) b...Show more |
1Ays Pro 1Secure Copy Content Protection And Content Locking Jun 17, 2026 Dec 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authentica...Show more |
1Wpdataaccess 1Wp Data Access Jun 17, 2026 Dec 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion |
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres...Show more |
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php. |
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.php. |
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php. |
SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php. |
Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article. |
Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search. |
1Broadcom 1Ca Network Flow Analysis Jun 17, 2026 Dec 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due to insufficient input validation, that could potentially allow an authenticated user to access sensi...Show more |
ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php. |
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection |
1Phpgurukul 1Employee Record Management System Jun 17, 2026 Dec 1, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php. |