← Back
CWE-89

20,764 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,764)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ays Pro
1Poll Maker
Jun 17, 2026
Aug 2, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the g...Show more
The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboardShow less
1Ays Pro
1Image Slider
Jun 17, 2026
Aug 2, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the...Show more
The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboardShow less
1Ays Pro
1Photo Gallery
Jun 17, 2026
Aug 2, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in S...Show more
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboardShow less
1Ays Pro
1Faq Builder
Jun 17, 2026
Aug 2, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL...Show more
The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboardShow less
1Ays Pro
1Popup Box
Jun 17, 2026
Aug 2, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB c...Show more
The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboardShow less
1Ays Pro
1Survey Maker
Jun 17, 2026
Aug 2, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls...Show more
The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboardShow less
1Ays Pro
1Popup Box
Jun 17, 2026
Aug 2, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_res...Show more
The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboardShow less
1Ays Pro
1Portfolio Responsive Gallery
Jun 17, 2026
Aug 2, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Ga...Show more
The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Gallery WordPress plugin before 1.1.8 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboardShow less
1Ays Pro
1Quiz Maker
Jun 17, 2026
Aug 2, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard
1Peel
1Peel Shopping
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection...Show more
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.Show less
1Phone Shop Sales Management System Project
1Phone Shop Sales Management System
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
1Online Covid Vaccination Scheduler System Project
1Online Covid Vaccination Scheduler System
Jun 17, 2026
Jul 30, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker...Show more
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.Show less
1Online Pet Shop We App Project
1Online Pet Shop We App
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter.
1Simple Food Website Project
1Simple Food Website
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.
1Basic Shopping Cart Project
1Basic Shopping Cart
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.
1Nukeviet
1Nukeviet
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.
1Nukeviet
1Nukeviet
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.
1Ectouch
1Ectouch
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..
1Metinfo
1Metinfo
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.
1Whatsns
1Whatsns
Jun 17, 2026
Jul 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm.