← Back
CWE-89

20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,763)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Doctor Appointment System Project
1Doctor Appointment System
Jun 17, 2026
Mar 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
1Doctor Appointment System Project
1Doctor Appointment System
Jun 17, 2026
Mar 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
1Xwiki
1Xwiki
Jun 17, 2026
Mar 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Rating Script Service e...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Rating Script Service expose an API to perform SQL requests without escaping the from and where search arguments. This might lead to an SQL script injection quite easily for any user having Script rights on XWiki. The problem has been patched in XWiki 12.9RC1. The only workaround besides upgrading XWiki would be to uninstall the Ratings API in XWiki from the Extension Manager.Show less
1Hpe
1Network Orchestrator
Jun 17, 2026
Mar 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection.
1It Recht Kanzlei
1It Recht Kanzlei
Jun 17, 2026
Mar 19, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.
1Wowonder
1Wowonder
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.
1Webnus
1Modern Events Calendar Lite
Jun 17, 2026
Mar 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an...Show more
Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.Show less
1Accesspressthemes
1Accesspress Social Icons
Jun 17, 2026
Mar 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
1Webfactoryltd
1301 Redirects
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL i...Show more
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.Show less
1Sigmaplugin
1Advanced Database Cleaner
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.
1Connekthq
1Ajax Load More
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.
110web
1Photo Gallery
Jun 17, 2026
Mar 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
1Ajdg
1Adrotate
Jun 17, 2026
Mar 18, 2021
N/A· v4
5.5 MEDIUM· v3
5.5 MEDIUM· v2
Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.
1Adenion
1Blog2social
Jun 17, 2026
Mar 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.
110web
1Slider
Jun 17, 2026
Mar 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such...Show more
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.Show less
1Cleantalk
1Anti Spam
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).
1Weplugins
1Wp Maps
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
1Contact Form Submissions Project
1Contact Form Submissions
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+)
1Seopanel
1Seo Panel
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.
1Hgiga
4Msr45 Isherlock Antispam
Msr45 Isherlock UserSsr45 Isherlock Antispam+1 more
Jun 17, 2026
Mar 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.