← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nukeviet
1Nukeviet
Jun 17, 2026
Dec 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent).
1Mantisbt
1Mantisbt
Jun 17, 2026
Dec 30, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
1Egavilanmedia
1User Registration And Login System With Admin Panel
Jul 9, 2026
Dec 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
1Dotcms
1Dotcms
Jun 17, 2026
Dec 30, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy para...Show more
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.Show less
1Agentejo
1Cockpit
Jun 17, 2026
Dec 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
1Agentejo
1Cockpit
Jun 17, 2026
Dec 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
1Agentejo
1Cockpit
Jun 17, 2026
Dec 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
1Joomla
1Joomla
Jun 17, 2026
Dec 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Joomla! 3.0.0 through 3.9.22. Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.
1Flamingo Project
1Flamingo
Jun 17, 2026
Dec 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
1Flamingo Project
1Flamingo
Jun 17, 2026
Dec 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
1Flamingo Project
1Flamingo
Jun 17, 2026
Dec 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
1Flamingo Project
1Flamingo
Jun 17, 2026
Dec 26, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.
1Phplist
1Phplist
Jun 17, 2026
Dec 25, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
1Egavilanmedia
1Egm Address Book
Jun 17, 2026
Dec 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
1Egavilanmedia
1Under Construction Page With Cpanel
Jun 17, 2026
Dec 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
1Steedos
1Steedos
Jun 17, 2026
Dec 23, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks su...Show more
Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.Show less
1Online Health Care System Project
1Online Health Care System
Jun 17, 2026
Dec 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.
1Library Management System Project
1Library Management System
Jun 17, 2026
Dec 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Dec 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
1Crk
1Business Platform
Jun 17, 2026
Dec 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.