CWE-89
20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,763)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database...Show more |
1College Management System Project 1College Management System Jun 17, 2026 May 24, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. |
SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecified vectors. |
1Control Webpanel 1Webpanel Jun 17, 2026 May 18, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter. |
In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's da...Show more |
The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue |
1Cleantalk 1Spam Protection, Antispam, Firewall Jun 17, 2026 May 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk...Show more |
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChanne...Show more |
1Cars Seller Auto Classifieds Script Project 1Cars Seller Auto Classifieds Script Jun 17, 2026 May 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id...Show more |
Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter. |
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection. |
A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-reset token of the admin....Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 May 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 May 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection....Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 May 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoCode parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. A...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 May 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoService parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 May 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injectio...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 May 10, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 May 10, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL inject...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 May 10, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injectio...Show more |