← Back
CWE-89

20,766 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,766)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1F5
1Big Ip Advanced Firewall Manager
Jun 17, 2026
Sep 14, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Co...Show more
On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This issue is exposed only when BIG-IP AFM is provisioned. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1Sap
4Landscape Transformation
Landscape Transformation Replication ServerS/4hana+1 more
Jun 17, 2026
Sep 14, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain acces...Show more
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.Show less
1Sap
1Business One
Jun 17, 2026
Sep 14, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.
1Apartment Visitors Management System Project
1Apartment Visitors Management System
Jun 17, 2026
Sep 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.
1Cozmoslabs
1Membership & Content Restriction Paid Member Subscriptions
Jun 17, 2026
Sep 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenti...Show more
The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.Show less
1Billminozzi
1Stop Bad Bots
Jun 17, 2026
Sep 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections
1Wpsimplebookingcalendar
1Wp Simple Booking Calendar
Jun 17, 2026
Sep 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL...Show more
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issueShow less
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Sep 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
1Smartypantsplugins
1Sp Rental Manager
Jun 17, 2026
Sep 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in ve...Show more
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.Show less
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Sep 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Sep 9, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
1Mypresta
1Customer Photo Gallery
Jun 17, 2026
Sep 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.
1Bluecms Project
1Bluecms
Jun 17, 2026
Sep 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
1Cliniccases
1Cliniccases
Jun 17, 2026
Sep 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.
1Ntracker
1Ntracker Usb Enterprise
Jun 17, 2026
Sep 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information...Show more
A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information.Show less
1Simple Water Refilling Station Management System Project
1Simple Water Refilling Station Management System
Jun 17, 2026
Sep 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.
1Geekwebsolution
1Embed Youtube Video
Jun 17, 2026
Sep 6, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
1Easy Testimonial Manager Project
1Easy Testimonial Manager
Jun 17, 2026
Sep 6, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection
1Comment Highlighter Project
1Comment Highlighter
Jun 17, 2026
Sep 6, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
1Swiftcrm
1Club Management Software
Jun 17, 2026
Sep 6, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.