← Back
CWE-89

20,778 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,778)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Attendance Management System Project
1Attendance Management System
Jun 17, 2026
Dec 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.
1Dell
1Emc Streaming Data Platform
Jun 17, 2026
Nov 30, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and r...Show more
Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.Show less
1Os4ed
1Opensis
Jun 17, 2026
Nov 30, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.ph...Show more
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.Show less
1Os4ed
1Opensis
Jun 17, 2026
Nov 30, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TIT...Show more
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.Show less
1Os4ed
1Opensis
Jun 17, 2026
Nov 30, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade...Show more
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.Show less
1Rosariosis
1Rosariosis
Jun 17, 2026
Nov 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) throu...Show more
An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.Show less
1Contest Gallery
1Contest Gallery
Jun 17, 2026
Nov 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from...Show more
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email addressShow less
1Ninjaforms
1Ninja Forms
Jun 17, 2026
Nov 29, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks
1Bannersky
1Bsk Pdf Manager
Jun 17, 2026
Nov 29, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue
1Wpexperts
1Mycred
Jun 17, 2026
Nov 29, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user
1Mandsconsulting
1Email Before Download
Jun 17, 2026
Nov 29, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues
1Sophos
1Unified Threat Management Up2date
Jun 17, 2026
Nov 26, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
1Wpwave
1Hide My Wp
Jun 17, 2026
Nov 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve...Show more
The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as "X-Forwarded-For." As a result, the malicious payload supplied in one of these IP address headers will be directly inserted into the SQL query, making SQL injection possible.Show less
1Dell
1Emc Idrac9 Firmware
Jun 17, 2026
Nov 23, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to cr...Show more
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability by sending a specially crafted malicious request to crash the webserver or cause information disclosure.Show less
1Dell
1Emc Idrac9 Firmware
Jun 17, 2026
Nov 23, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerabili...Show more
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to the affected application.Show less
1Mainwp
1Mainwp Child
Jun 17, 2026
Nov 23, 2021
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when th...Show more
The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installedShow less
4Debian
FedoraprojectPgbouncer+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 17, 2026
Nov 22, 2021
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encrypt...Show more
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.Show less
1Duplicate Post Project
1Duplicate Post
Jun 17, 2026
Nov 19, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Inject...Show more
The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrators, however the plugin presents the option to permit access to the Editor, Author, Contributor and Subscriber roles.Show less
3Debian
FedoraprojectRoundcube
3Debian Linux
FedoraWebmail
Jun 17, 2026
Nov 19, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
1Cisco
1Common Services Platform Collector
Jun 17, 2026
Nov 19, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnera...Show more
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnerability is due to insufficient input validation of uploaded files. An attacker could exploit this vulnerability by uploading a file containing a SQL query to the configuration dashboard. A successful exploit could allow the attacker to read restricted information from the CSPC SQL database.Show less