← Back
CWE-89

20,761 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,761)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
1Network Performance Monitor
Jun 17, 2026
Feb 12, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The s...Show more
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The specific flaw exists within the WriteToFile method. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges and reset the password for the Admin user. Was ZDI-CAN-11804.Show less
1Magento
1Magento
Jun 17, 2026
Feb 11, 2021
N/A· v4
9.1 CRITICAL· v3
6.5 MEDIUM· v2
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to...Show more
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.Show less
1Advantech
1Iview
Jun 17, 2026
Feb 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.
1Advantech
1Iview
Jun 17, 2026
Feb 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.
1Phpshe
1Phpshe
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.
1Phpok
1Phpok
Jun 17, 2026
Feb 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.
1College Management System Project
1College Management System
Jun 17, 2026
Feb 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.
1Librenms
1Librenms
Jun 17, 2026
Feb 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort...Show more
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.Show less
1Wpdatatables
1Wpdatatables
Jun 17, 2026
Feb 8, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Feb 5, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
1Zzzcms
1Zzzphp
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
1Rockoa
1Rockoa
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
1Rockoa
1Rockoa
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.
1Rockoa
1Rockoa
Jun 17, 2026
Feb 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php
1Sonicwall
6Sma 100 Firmware
Sma 200 FirmwareSma 210 Firmware+3 more
Aug 12, 2026
Feb 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability imp...Show more
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.Show less
1Rainbowfishsoftware
1Pacsone Server
Jun 17, 2026
Feb 3, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
1Koa2 Blog Project
1Koa2 Blog
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.
1Koa2 Blog Project
1Koa2 Blog
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signin page.
1Thinkjs
1Thinkjs
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
1Cmswing
1Cmswing
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands.