← Back
CWE-89

20,764 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,764)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jiangqie
1Official Website Mini Program
Jun 17, 2026
Sep 6, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues
1S Cms
1S Cms
Jun 17, 2026
Sep 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information.
1Os4ed
1Opensis
Jun 17, 2026
Sep 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.ph...Show more
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.Show less
1Os4ed
1Opensis
Jun 17, 2026
Sep 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php st...Show more
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the NamesList.php str parameter.Show less
1Os4ed
1Opensis
Jun 17, 2026
Sep 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php userna...Show more
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.Show less
1Os4ed
1Opensis
Jun 17, 2026
Sep 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this is...Show more
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for CVE-2020-6637.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Aug 31, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content includi...Show more
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.Show less
1Formtools
1Core
Jun 17, 2026
Aug 31, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manag...Show more
An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value...Show more
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value sup...Show more
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value...Show more
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value suppl...Show more
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.Show less
1Wow Estore
1Side Menu
Jun 17, 2026
Aug 30, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard before using it in SQL statement, leading to a SQL Injection issue
1Hexagongeospatial
1Geomedia Webmap
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.
1Youdiancms
1Youdiancms
Jun 17, 2026
Aug 27, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
1Wms Project
1Wms
Jun 17, 2026
Aug 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
1Cxuu
1Cxuucms
Jun 17, 2026
Aug 27, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php.
1Nuishop
1Nuishop
Jun 17, 2026
Aug 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/.
1Chachethq
1Cachet
Jun 17, 2026
Aug 26, 2021
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability t...Show more
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The original repository of Cachet <https://github.com/CachetHQ/Cachet> is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.Show less
1Hucart
1Hucart
Jun 17, 2026
Aug 26, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.