← Back
CWE-89

20,766 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,766)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Oct 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or d...Show more
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 207506.Show less
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Oct 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or d...Show more
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.Show less
1Wp Bannerize Project
1Wp Bannerize
Jun 17, 2026
Oct 6, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnera...Show more
The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.Show less
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Oct 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid param...Show more
A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.Show less
1Lodging Reservation Management System Project
1Lodging Reservation Management System
Jun 17, 2026
Oct 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
1Meowapps
1Meow Gallery
Jun 17, 2026
Oct 4, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to...Show more
The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulated in a way that could lead to data disclosure and arbitrary objects to be deserialized.Show less
1Thycotic
1Secret Server
Jun 17, 2026
Oct 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions are 10.9.000032 through 11.0.000006.
1Emlog
1Emlog
Jun 17, 2026
Oct 1, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
emlog v6.0.0 contains a SQL injection via /admin/comment.php.
1Hotel And Lodge Booking Management System Project
1Hotel And Lodge Booking Management System
Jun 17, 2026
Oct 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer,...Show more
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.Show less
1Online Food Ordering Web App Project
1Online Food Ordering Web App
Jun 17, 2026
Oct 1, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and ret...Show more
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.Show less
1Online Shopping System Advanced Project
1Online Shopping System Advanced
Jun 17, 2026
Oct 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
1Online Shopping System Advanced Project
1Online Shopping System Advanced
Jun 17, 2026
Oct 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
1Flamecms Project
1Flamecms
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.
1Flamecms Project
1Flamecms
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Sep 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.
1Thinkphp
1Thinkphp
Jun 17, 2026
Sep 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.
1Surelinesystems
1Sureedge Migrator
Jun 17, 2026
Sep 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360.
1Gilacms
1Gila Cms
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
GilaCMS v1.11.4 was discovered to contain a SQL injection vulnerability via the $_GET parameter in /src/core/controllers/cm.php.
1Stylemixthemes
1Ulisting
Jun 17, 2026
Sep 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.