← Back
CWE-89

20,761 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,761)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cmswing
1Cmswing
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
1Cmswing
1Cmswing
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
1Yccms
1Yccms
Jun 17, 2026
Feb 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
1Vmware
1Spring Cloud Task
Jun 17, 2026
Jan 27, 2021
N/A· v4
6.0 MEDIUM· v3
6.5 MEDIUM· v2
In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.
1Vmware
1Spring Cloud Data Flow
Jun 17, 2026
Jan 27, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In Spring Cloud Data Flow, versions 2.6.x prior to 2.6.5, versions 2.5.x prior 2.5.4, an application is vulnerable to SQL injection when requesting task execution.
1Spotweb Project
1Spotweb
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-355...Show more
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.Show less
1Local Services Search Engine Management System Project
1Local Services Search Engine Management System
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this vulnerability, an attacker can bypass the login page.
1Student Result Management System Project
1Student Result Management System
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.
1Egavilanmedia
1User Registration And Login System With Admin Panel
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
1Mingsoft
1Mcms
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
1Hyweb
1Hycms J1
Jun 17, 2026
Jan 22, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Hyweb HyCMS-J1's API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands without privilege.
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 20, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more informati...Show more
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more informati...Show more
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Sd Wan Vmanage
Jun 17, 2026
Jan 20, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilitie...Show more
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An attacker could exploit these vulnerabilities by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system.Show less
1Cisco
1Smart Software Manager On Prem
Jun 17, 2026
Jan 20, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Smart Software Manager Satellite could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exis...Show more
A vulnerability in the web-based management interface of Cisco Smart Software Manager Satellite could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates values within SQL queries. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system.Show less
1Cisco
2Unified Communications Manager
Unified Communications Manager Im And Presence Service
Jun 17, 2026
Jan 20, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system....Show more
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and could allow an attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
2Unified Communications Manager
Unified Communications Manager Im And Presence Service
Jun 17, 2026
Jan 20, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system....Show more
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and could allow an attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
2Unified Communications Manager
Unified Communications Manager Im And Presence Service
Jun 17, 2026
Jan 20, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system....Show more
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and could allow an attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Ibm
1Security Guardium
Jun 17, 2026
Jan 20, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end...Show more
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.Show less
1Prestashop
1Prestashop
Jun 17, 2026
Jan 20, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.