← Back
CWE-89

20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,763)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tracefinanacial
1Crestbridge
Jun 17, 2026
Jun 10, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.
1Progress
1Moveit Transfer
Jun 17, 2026
Jun 9, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (...Show more
In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in SILUtility.vb in MOVEit.DMZ.WebApp in the MOVEit Transfer web app. This could allow an authenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database and/or execute SQL statements that alter or delete database elements.Show less
1Esri
1Arcgis Server
Jun 17, 2026
Jun 7, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets)...Show more
A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets). Web Services that use file based data sources (file Geodatabase or Shape Files or tile cached services) are unaffected by this issue.Show less
1Veronalabs
1Wp Statistics
Jun 17, 2026
Jun 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been acc...Show more
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.Show less
1Video Embed Box Project
1Video Embed Box
Jun 17, 2026
Jun 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users...Show more
The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.Show less
1Zavedil
1Flightlog
Jun 17, 2026
Jun 7, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using them a SQL statement, leading to SQL injections exploitable by editor and administrator users
1Appcms
1Appcms
Jun 17, 2026
Jun 3, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database information.
1Fangfa
1Fdcms
Jun 17, 2026
Jun 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.class.php.
1Online Shopping Alphaware Project
1Online Shopping Alphaware
Jun 17, 2026
Jun 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
1Pharmacy Medical Store And Sale Point Project
1Pharmacy Medical Store And Sale Point
Jun 17, 2026
Jun 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases...Show more
The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.Show less
1Synology
1Photo Station
Jun 17, 2026
Jun 2, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQ...Show more
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail component in Synology Photo Station before 6.8.14-3500 allows remote attackers users to execute arbitrary SQL commands via unspecified vectors.Show less
1Synology
1Photo Station
Jun 17, 2026
Jun 2, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL...Show more
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to execute arbitrary SQL command via unspecified vectors.Show less
1Bigtreecms
1Bigtree Cms
Jun 17, 2026
Jun 1, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New Feed...Show more
A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New Feed' function.Show less
1Synology
1Media Server
Jun 17, 2026
Jun 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via...Show more
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.Show less
1Bold Themes
1Bello
Jun 17, 2026
Jun 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my...Show more
The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issuesShow less
1In4velocity
1In4suite Erp
Jun 17, 2026
Jun 1, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
1Phpgurukul
1Covid19 Testing Management System
Jun 17, 2026
May 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
1Vfairs
1Vfairs
Jul 9, 2026
May 26, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
1Emlog
1Emlog
Jun 17, 2026
May 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive data via admin/navbar.php?action=add_page.
1Zzcms
1Zzcms
Jun 17, 2026
May 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.