← Back
CWE-89

20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,763)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpnuke
1Php Nuke
Jun 17, 2026
Apr 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to be two letters, and the OrderBy field is...Show more
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to be two letters, and the OrderBy field is not validated to be one of LASTNAME, CITY, or STATE.Show less
1Citsmart
1Citsmart
Jun 17, 2026
Apr 6, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
1Themeum
1Tutor Lms
Jun 17, 2026
Apr 5, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited...Show more
The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.Show less
1Themeum
1Tutor Lms
Jun 17, 2026
Apr 5, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.
1Themeum
1Tutor Lms
Jun 17, 2026
Apr 5, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students...Show more
The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.Show less
1Themeum
1Tutor Lms
Jun 17, 2026
Apr 5, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by st...Show more
The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.Show less
1Themeum
1Tutor Lms
Jun 17, 2026
Apr 5, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by studen...Show more
The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.Show less
1Eng
1Knowage
Jun 17, 2026
Apr 5, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report.
1Piwigo
1Piwigo
Jun 17, 2026
Apr 2, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
1Latrix Project
1Latrix
Jun 17, 2026
Apr 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to information disclosure and code execution.
1Fireeye
1Email Malware Protection System
Jun 17, 2026
Apr 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the...Show more
eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3.Show less
1Fireeye
1Email Malware Protection System
Jun 17, 2026
Apr 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3....Show more
eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3. NOTE: this is different from CVE-2020-25034 and affects newer versions of the software.Show less
1Pbootcms
1Pbootcms
Jun 17, 2026
Mar 31, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.
1Simple College Project
1Simple College
Jun 17, 2026
Mar 31, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the...Show more
A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.Show less
1Ovidentia
1Ovidentia
Jun 17, 2026
Mar 30, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text region or in source code.
1Xerox
10Altalink B8045 Firmware
Altalink B8055 FirmwareAltalink B8065 Firmware+7 more
Jun 17, 2026
Mar 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities.
1Invigo
1Automatic Device Management
Jun 17, 2026
Mar 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the d...Show more
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.Show less
1Thinksaas
1Thinksaas
Jun 17, 2026
Mar 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.
1Doctor Appointment System Project
1Doctor Appointment System
Jun 17, 2026
Mar 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
1Doctor Appointment System Project
1Doctor Appointment System
Jun 17, 2026
Mar 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.