← Back
CWE-89

20,764 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,764)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Local Services Search Engine Management System Project
1Local Services Search Engine Management System
Jun 17, 2026
Aug 19, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data from the database.
1Find A Place Ljcms Project
1Find A Place Ljcms
Jun 17, 2026
Aug 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
1Seacms
1Seacms
Jun 17, 2026
Aug 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
1Aitecms
1Aitecms
Jun 17, 2026
Aug 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".
1Tp Shop
1Tp Shop
Jun 17, 2026
Aug 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Aug 17, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id parameter in the 'entities/fields page (mulitple_edit or copy_selected or e...Show more
An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The entities_id parameter in the 'entities/fields page (mulitple_edit or copy_selected or export function) is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.Show less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Aug 17, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQ...Show more
An exploitable SQL injection vulnerability exists in the ‘entities/fields’ page of the Rukovoditel Project Management App 2.7.2. The heading_field_id parameter in ‘‘entities/fields’ page is vulnerable to authenticated SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.Show less
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Aug 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
1Newsletter Project
1Newsletter
Jun 17, 2026
Aug 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
1Dated News Project
1Dated News
Jun 17, 2026
Aug 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
1Nagios
1Nagios Xi
Jun 17, 2026
Aug 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.
1J2eefast
1J2eefast
Jun 17, 2026
Aug 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parameter to fast/sys/role/authUser/list, rela...Show more
J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parameter to fast/sys/role/authUser/list, related to the use of ${} to join SQL statements.Show less
1Nuance
1Winscribe Dictation
Jun 17, 2026
Aug 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situa...Show more
The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword parameter.Show less
1Metinfo
1Metinfo
Jun 17, 2026
Aug 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.
1Gxlcms
1Gxlcms
Jun 17, 2026
Aug 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
1Foxitsoftware
2Foxit Reader
Phantompdf
Jun 17, 2026
Aug 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
1Rconfig
1Rconfig
Jun 17, 2026
Aug 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php.
1Rconfig
1Rconfig
Jun 17, 2026
Aug 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and access sensitive database information.
1Otrs
2Otrs
Otrs Itsm
Nov 21, 2024
Aug 9, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands vi...Show more
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to Kernel/Output/HTML/PreferencesCustomQueue.pm, Kernel/System/CustomerCompany.pm, Kernel/System/Ticket/IndexAccelerator/RuntimeDB.pm, Kernel/System/Ticket/IndexAccelerator/StaticDB.pm, and Kernel/System/TicketSearch.pm.Show less
1Wow Estore
1Side Menu
Jun 17, 2026
Aug 9, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to mana...Show more
The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from the browser when building an SQL statement. Users with the administrator role or permission to manage this plugin could perform an SQL Injection attack.Show less