CWE-89
20,766 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,766)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 1Big Ip Advanced Firewall Manager Jun 17, 2026 Sep 14, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Co...Show more |
1Sap 4Landscape Transformation Landscape Transformation Replication ServerS/4hana+1 moreJun 17, 2026 Sep 14, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain acces...Show more |
SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained. |
1Apartment Visitors Management System Project 1Apartment Visitors Management System Jun 17, 2026 Sep 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE. |
1Cozmoslabs 1Membership & Content Restriction Paid Member Subscriptions Jun 17, 2026 Sep 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenti...Show more |
The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections |
1Wpsimplebookingcalendar 1Wp Simple Booking Calendar Jun 17, 2026 Sep 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Sep 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. |
1Smartypantsplugins 1Sp Rental Manager Jun 17, 2026 Sep 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in ve...Show more |
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items |
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items |
1Mypresta 1Customer Photo Gallery Jun 17, 2026 Sep 8, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection. |
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php. |
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter. |
1Ntracker 1Ntracker Usb Enterprise Jun 17, 2026 Sep 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information...Show more |
1Simple Water Refilling Station Management System Project 1Simple Water Refilling Station Management System Jun 17, 2026 Sep 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter. |
1Geekwebsolution 1Embed Youtube Video Jun 17, 2026 Sep 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. |
1Easy Testimonial Manager Project 1Easy Testimonial Manager Jun 17, 2026 Sep 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection |
1Comment Highlighter Project 1Comment Highlighter Jun 17, 2026 Sep 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. |
1Swiftcrm 1Club Management Software Jun 17, 2026 Sep 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. |