← Back
CWE-89

20,764 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,764)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hucart
1Hucart
Jun 17, 2026
Aug 26, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
1Wdoyo
1Doyocms
Jun 17, 2026
Aug 26, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
1Thinkphp Zcms Project
1Thinkphp Zcms
Jun 17, 2026
Aug 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
1Ecisp
1Espcms P8
Jun 17, 2026
Aug 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information...Show more
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information.Show less
1Philips
1Tasy Electronic Medical Record
Jun 17, 2026
Aug 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.
1Philips
1Tasy Electronic Medical Record
Jun 17, 2026
Aug 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.
1Smartdatasoft
1Smartblog
Jun 17, 2026
Aug 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controll...Show more
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.Show less
1Cerner
1Mobile Care
Jun 17, 2026
Aug 24, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary sys...Show more
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.Show less
1Nimble3
1M Vslider
Jun 17, 2026
Aug 23, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator...Show more
The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role.Show less
1Roosty
1Diary Availability Calendar
Jun 17, 2026
Aug 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to...Show more
The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is lacking any CSRF and capability check, making it available to any authenticated user.Show less
1Freelancetoindia
1Paytm Pay
Jun 17, 2026
Aug 23, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection...Show more
The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issueShow less
1Timeline Calendar Project
1Timeline Calendar
Jun 17, 2026
Aug 23, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Oth...Show more
The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the pluginShow less
1Simple Events Calendar Project
1Simple Events Calendar
Jun 17, 2026
Aug 23, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injecti...Show more
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issueShow less
1Edit Comments Project
1Edit Comments
Jun 17, 2026
Aug 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue
1Broken Link Manager Project
1Broken Link Manager
Jun 17, 2026
Aug 23, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL inject...Show more
The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issueShow less
1Quantumcloud
1Slider Hero
Jun 17, 2026
Aug 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users wi...Show more
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.Show less
1Satollo
1Giveaway
Jun 17, 2026
Aug 23, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.
1Prestahome
1Blog
Jun 17, 2026
Aug 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Aug 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Aug 19, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.