CWE-89
20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,763)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed description --- Given the following request: ``` GET /InstallTab/exportFld...Show more |
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreC...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulner...Show more |
A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information. |
A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information. |
SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information |
1Export Users With Meta Project 1Export Users With Meta Jun 17, 2026 Jul 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL I...Show more |
A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to execute arbitrary SQL commands via the id parameter to mesdocs.ajax.php in azurWebEngine/eShop. By defau...Show more |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 Jul 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. |
IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete in...Show more |
1Phpgurukul 1Teachers Record Management System Jun 17, 2026 Jul 1, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit...Show more |
Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). |
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php. |
SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php. |
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. |
1Online Pet Shop Web Application Project 1Online Pet Shop Web Application Jun 17, 2026 Jun 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload |
1Fidelissecurity 2Deception NetworkJun 17, 2026 Jun 25, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on t...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 Jun 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis so...Show more |
SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn. |
DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of DHIS2. This vulnerability affects the /...Show more |