CWE-89
20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,763)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Connectwise 1Connectwise Automate Jun 17, 2026 Jun 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrativ...Show more |
SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php. |
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. |
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. |
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. |
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. |
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php. |
SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php. |
SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. . |
SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php. |
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php. |
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php. |
1Alumni Management System Project 1Alumni Management System Jun 17, 2026 Jun 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php. |
The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks |
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitis...Show more |
The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL stat...Show more |
1Xllentech 1English Islamic Calendar Jun 17, 2026 Jun 14, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement,...Show more |
The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182). |
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command C...Show more |
Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03. |