CWE-89
20,764 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,764)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the g...Show more |
The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the...Show more |
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in S...Show more |
The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL...Show more |
The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB c...Show more |
The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls...Show more |
The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_res...Show more |
1Ays Pro 1Portfolio Responsive Gallery Jun 17, 2026 Aug 2, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Ga...Show more |
The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters before using them in SQL statements, leading to SQL injection issues in the admin dashboard |
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection...Show more |
1Phone Shop Sales Management System Project 1Phone Shop Sales Management System Jun 17, 2026 Jul 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. |
1Online Covid Vaccination Scheduler System Project 1Online Covid Vaccination Scheduler System Jun 17, 2026 Jul 30, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker...Show more |
1Online Pet Shop We App Project 1Online Pet Shop We App Jun 17, 2026 Jul 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter. |
1Simple Food Website Project 1Simple Food Website Jun 17, 2026 Jul 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin. |
1Basic Shopping Cart Project 1Basic Shopping Cart Jun 17, 2026 Jul 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin. |
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php. |
SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php. |
SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php.. |
SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php. |
SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm. |