← Back
CWE-89

20,768 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,768)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Oct 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.
1Phpgurukul
1Ifsc Code Finder
Jun 17, 2026
Oct 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
1Proofpoint
1Insider Threat Management Server
Jun 17, 2026
Oct 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input validation on the database name parameter required in certain unauthen...Show more
Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input validation on the database name parameter required in certain unauthenticated APIs. A malicious URL visited by anyone with network access to the server could be used to blindly execute arbitrary SQL statements on the backend database. Version 7.12.0 and all versions prior to 7.11.2 are affected.Show less
1Froxlor
1Froxlor
Jun 17, 2026
Oct 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
1Os4ed
1Opensis
Jun 17, 2026
Oct 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONT_PSWD parameters in HoldAddressFields.php.
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.Show less
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.Show less
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.Show less
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.Show less
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.Show less
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.Show less
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.Show less
1Siemens
1Sinec Nms
Jun 17, 2026
Oct 12, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker that is able to import firmware containers to an affected system could execute arbitrary commands in the loca...Show more
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker that is able to import firmware containers to an affected system could execute arbitrary commands in the local database.Show less
1Os4ed
1Opensis
Jun 17, 2026
Oct 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
1Os4ed
1Opensis
Jun 17, 2026
Oct 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file.
1Rconfig
1Rconfig
Jul 9, 2026
Oct 11, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may success...Show more
rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the server and access it remotely.Show less
1Ays Pro
1Poll Maker
Jun 17, 2026
Oct 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing at...Show more
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.Show less
1Webtareas Project
1Webtareas
Jun 17, 2026
Oct 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST paramet...Show more
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.Show less
1Intelliants
1Subrion Cms
Jun 17, 2026
Oct 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
1Opensns
1Opensns
Jun 17, 2026
Oct 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter.