← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hgiga
1Oaklouds Openid
Jun 17, 2026
Jan 19, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.
1Hgiga
1Oaklouds Openid
Jun 17, 2026
Jan 19, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
1Flatcore
1Flatcore
Jun 17, 2026
Jan 15, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieve...Show more
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieves the file contents of the specified folder) was found to be accepting malicious user input without proper sanitization, thus leading to SQL injection. Database related information can be successfully retrieved.Show less
1Dell
2Emc Avamar Server
Emc Integrated Data Protection Appliance
Jun 17, 2026
Jan 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of ce...Show more
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write access to application data. Exploitation may lead to leakage or deletion of sensitive backup data; hence the severity is Critical. Dell EMC recommends customers to upgrade at the earliest opportunity.Show less
1Fortinet
1Fortiweb
Jun 17, 2026
Jan 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a...Show more
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.Show less
1Microsoft
1Sql Server
Jun 17, 2026
Jan 12, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Microsoft SQL Elevation of Privilege Vulnerability
1Sap
1Business Warehouse
Jun 17, 2026
Jan 12, 2021
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute with...Show more
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL injection vulnerability which can fully compromise the affected SAP system.Show less
1Vanderbilt
1Redcap
Jun 17, 2026
Jan 12, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the dat...Show more
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.Show less
2Cacti
Fedoraproject
2Cacti
Fedora
Jun 17, 2026
Jan 11, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to r...Show more
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.Show less
1Zzcms
1Zzcms
Jul 9, 2026
Jan 11, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
1Medicalexpo
1Ecs Imaging
Jun 17, 2026
Jan 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in...Show more
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Invisioncommunity
1Ips Community Suite
Jun 17, 2026
Jan 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php).
1Restaurant Reservation System Project
1Restaurant Reservation System
Jun 17, 2026
Jan 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation....Show more
Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.Show less
1Orangehrm
1Orangehrm
Jun 17, 2026
Jan 5, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter...Show more
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.Show less
1Ispconfig
1Ispconfig
Jun 17, 2026
Jan 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ISPConfig before 3.2.2 allows SQL injection.
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Jan 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilitie...Show more
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.Show less
1Ipeak
1Ipeakcms
Jun 17, 2026
Jan 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.
1Cse Bookstore Project
1Cse Bookstore
Jun 17, 2026
Jan 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will...Show more
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.Show less
1Hgiga
4Msr45 Isherlock Antispam
Msr45 Isherlock UserSsr45 Isherlock Antispam+1 more
Jun 17, 2026
Dec 31, 2020
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
1Hgiga
4Msr45 Isherlock Antispam
Msr45 Isherlock UserSsr45 Isherlock Antispam+1 more
Jun 17, 2026
Dec 31, 2020
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.