CWE-89
20,778 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,778)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Attendance Management System Project 1Attendance Management System Jun 17, 2026 Dec 1, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function. |
1Dell 1Emc Streaming Data Platform Jun 17, 2026 Nov 30, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and r...Show more |
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.ph...Show more |
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TIT...Show more |
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade...Show more |
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) throu...Show more |
1Contest Gallery 1Contest Gallery Jun 17, 2026 Nov 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from...Show more |
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks |
The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue |
The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user |
1Mandsconsulting 1Email Before Download Jun 17, 2026 Nov 29, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues |
1Sophos 1Unified Threat Management Up2date Jun 17, 2026 Nov 26, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8. |
The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve...Show more |
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to cr...Show more |
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerabili...Show more |
The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when th...Show more |
4Debian FedoraprojectPgbouncer+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Nov 22, 2021 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encrypt...Show more |
1Duplicate Post Project 1Duplicate Post Jun 17, 2026 Nov 19, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Inject...Show more |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Nov 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. |
1Cisco 1Common Services Platform Collector Jun 17, 2026 Nov 19, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnera...Show more |