← Back
CWE-89

20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,763)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Connectwise
1Connectwise Automate
Jun 17, 2026
Jun 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrativ...Show more
An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status responses.Show less
174cms
174cms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.
174cms
174cms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
174cms
174cms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
174cms
174cms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
174cms
174cms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
1Shopex
1Ecshop
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.
1Shopex
1Ecshop
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.
1Shopex
1Ecshop
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. .
1Phpcms
1Phpcms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
1Phpcms
1Phpcms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
1Dedecms
1Dedecms
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Jun 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
1Kohsei Works
1Yes/no Chart
Jun 17, 2026
Jun 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks
1Wow Estore
1Side Menu
Jun 17, 2026
Jun 14, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitis...Show more
The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Administrator users takes the did GET parameter and uses it into an SQL statement without proper sanitisation, validation or escaping, therefore leading to a SQL Injection issueShow less
1Sendit Project
1Sendit
Jun 17, 2026
Jun 14, 2021
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL stat...Show more
The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator users does not sanitise, validate or escape the id_lista POST parameter before using it in SQL statement, therefore leading to Blind SQL Injection.Show less
1Xllentech
1English Islamic Calendar
Jun 17, 2026
Jun 14, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement,...Show more
When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection.Show less
1Advantech
1Iview
Jun 17, 2026
Jun 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).
1Gallagher
1Command Centre
Jun 17, 2026
Jun 11, 2021
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command C...Show more
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions.Show less
1Tracefinanacial
1Crestbridge
Jun 17, 2026
Jun 10, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.