← Back
CWE-89

20,778 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,778)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Recruitment Management System Project
1Recruitment Management System
Jun 17, 2026
Nov 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each...Show more
The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.Show less
1Wp Buy
1Seo Redirection 301 Redirect Manager
Jun 17, 2026
Nov 17, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it...Show more
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installedShow less
1Xwp
1Stream
Jun 17, 2026
Nov 17, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.
1Email Log Project
1Email Log
Jun 17, 2026
Nov 17, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections
1Meddata
1Hbys
Jun 17, 2026
Nov 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.
1Meddata
1Hbys
Jun 17, 2026
Nov 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.
1Ipack
1Scada Automation
Jun 17, 2026
Nov 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Handling of Parameters vulnerability in Ipack Automation Systems Ipack SCADA Software allows : Blind SQL Injection.This issue affects Ipack SCADA Software: from unspecified before 1.1.0.
1Oretnom23
1Online Learning System
Jun 17, 2026
Nov 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerabli...Show more
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.Show less
1Montala
1Resourcespace
Jun 17, 2026
Nov 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attack...Show more
A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An attacker who gets an admin user session cookie can use the session cookie to execute arbitrary code on the server.Show less
1Talariax
1Sendquick Alert Plus Server Admin
Jun 17, 2026
Nov 14, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.
1Zohocorp
1Manageengine Network Configuration Manager
Jun 17, 2026
Nov 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.
1Zohocorp
1Manageengine Network Configuration Manager
Jun 17, 2026
Nov 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.
1Wpaffiliatemanager
1Affiliates Manager
Jun 17, 2026
Nov 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue
1Wclovers
1Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM -...Show more
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the withdrawal_vendor parameter before using it in a SQL statement, allowing low privilege users such as Subscribers to perform SQL injection attacksShow less
1Wp Buy
1Visitor Traffic Real Time Statistics
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL s...Show more
The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issueShow less
1Asgaros
1Asgaros Forum
Jun 17, 2026
Nov 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue
1Draftpress
1Header Footer Code Manager
Jun 17, 2026
Nov 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, lead...Show more
The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injectionsShow less
1Genetechsolutions
1Pie Register
Jun 17, 2026
Nov 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the...Show more
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.Show less
1Feataholic
1Maz Loader
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injecti...Show more
The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.Show less
1Unlimited Popups Project
1Unlimited Popups
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection