CWE-89
20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,763)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 Mar 18, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. |
The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege. |
The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Mar 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. |
SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3). |
SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3). |
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3). |
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files. |
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass. |
1Thedaylightstudio 1Fuel Cms Jun 17, 2026 Mar 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabil...Show more |
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the child...Show more |
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter. |
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote att...Show more |
A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Multiple vulnerabilities in the API of AirWave could allow an authenticated remote att...Show more |
1Doctor Appointment System Project 1Doctor Appointment System Jun 17, 2026 Mar 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page. |
1Courier Management System Project 1Courier Management System Jun 17, 2026 Mar 4, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '. |
1Courier Management System Project 1Courier Management System Jun 17, 2026 Mar 4, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php |
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request. |
In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise. |
LMA ISIDA Retriever 5.2 allows SQL Injection. |