CWE-89
20,764 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,764)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field. |
A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter. |
1Thinkphp Zcms Project 1Thinkphp Zcms Jun 17, 2026 Aug 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add. |
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information...Show more |
1Philips 1Tasy Electronic Medical Record Jun 17, 2026 Aug 24, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter. |
1Philips 1Tasy Electronic Medical Record Jun 17, 2026 Aug 24, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter. |
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controll...Show more |
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary sys...Show more |
The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator...Show more |
1Roosty 1Diary Availability Calendar Jun 17, 2026 Aug 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to...Show more |
The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection...Show more |
1Timeline Calendar Project 1Timeline Calendar Jun 17, 2026 Aug 23, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Oth...Show more |
1Simple Events Calendar Project 1Simple Events Calendar Jun 17, 2026 Aug 23, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injecti...Show more |
1Edit Comments Project 1Edit Comments Jun 17, 2026 Aug 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue |
1Broken Link Manager Project 1Broken Link Manager Jun 17, 2026 Aug 23, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL inject...Show more |
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users wi...Show more |
The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page. |
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter. |
SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'. |
2Misp Misp Project2Misp MispJun 22, 2026 Aug 19, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value. |