CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data. |
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data. |
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieve...Show more |
1Dell 2Emc Avamar Server Emc Integrated Data Protection ApplianceJun 17, 2026 Jan 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of ce...Show more |
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a...Show more |
Microsoft SQL Elevation of Privilege Vulnerability |
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute with...Show more |
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the dat...Show more |
2Cacti Fedoraproject2Cacti FedoraJun 17, 2026 Jan 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to r...Show more |
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection). |
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in...Show more |
1Invisioncommunity 1Ips Community Suite Jun 17, 2026 Jan 8, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php). |
1Restaurant Reservation System Project 1Restaurant Reservation System Jun 17, 2026 Jan 7, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation....Show more |
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter...Show more |
ISPConfig before 3.2.2 allows SQL injection. |
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilitie...Show more |
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page. |
1Cse Bookstore Project 1Cse Bookstore Jun 17, 2026 Jan 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will...Show more |
1Hgiga 4Msr45 Isherlock Antispam Msr45 Isherlock UserSsr45 Isherlock Antispam+1 moreJun 17, 2026 Dec 31, 2020 N/A· v4 7.6 HIGH· v3 6.5 MEDIUM· v2 HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages. |
1Hgiga 4Msr45 Isherlock Antispam Msr45 Isherlock UserSsr45 Isherlock Antispam+1 moreJun 17, 2026 Dec 31, 2020 N/A· v4 7.6 HIGH· v3 6.5 MEDIUM· v2 HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter. |