← Back
CWE-89

20,766 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,766)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Podlove
1Podlove Podcast Publisher
Jun 17, 2026
Sep 27, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category'...Show more
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.Show less
1Os4ed
1Opensis
Jun 17, 2026
Sep 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. The cp_id_miss_attn parameter from TakeAttendance.php is vulnerable to S...Show more
A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. The cp_id_miss_attn parameter from TakeAttendance.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request as a user with access to "Take Attendance" functionality to trigger this vulnerability.Show less
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Sep 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.
1Schiocco
1Support Board Chat And Help Desk
Jun 17, 2026
Sep 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL st...Show more
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.Show less
1Offshorewebmaster
1Availability Calendar
Jun 17, 2026
Sep 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user a...Show more
The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+Show less
1Dpl
1Product Feed On Woocommerce
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL s...Show more
The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_id` POST parameter which is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.Show less
1Wp Board Project
1Wp Board
Jun 17, 2026
Sep 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. This is a time...Show more
The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query ran twice.Show less
1Wpagecontact Project
1Wpagecontact
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature...Show more
The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributorsShow less
1Solvercircle
1Wp Icommerce
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feat...Show more
The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributorsShow less
1Wp Domain Redirect Project
1Wp Domain Redirect
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
1Wp Display Users Project
1Wp Display Users
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
1Ombu
1The Sorter
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
1Webpsilon
1Responsive 3d Slider
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injectio...Show more
The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query is ran twice.Show less
1Activemedia
1Microcopy
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting to a SQL statement, le...Show more
The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.Show less
1Bestiaweb
1Gseor
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Sep 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Sep 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.
1Sap
3Dmis
S4coreSapscore
Jun 17, 2026
Sep 15, 2021
N/A· v4
9.1 CRITICAL· v3
6.5 MEDIUM· v2
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker wit...Show more
DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to Superuser account, leading to SQL Injection vulnerability, that highly impacts systems Confidentiality, Integrity and Availability.Show less
1Metinfo
1Metinfo
Jun 17, 2026
Sep 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
1Kliqqi
1Kliqqi Cms
Jun 17, 2026
Sep 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.