CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Abb 2Symphony + Historian Symphony + OperationsJun 17, 2026 Dec 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shu...Show more |
1Phpgurukul 1Online Marriage Registration System Jun 17, 2026 Dec 21, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection. |
An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities. |
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php. |
SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter. |
1Egavilanmedia 1Ecm Address Book Jul 9, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user. |
SQL injection vulnerability in the wp_where function in WeiPHP 5.0. |
The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection. |
Time-based SQL injection exists in Spotweb 1.4.9 via the query string. |
1Keysight 1Keysight Database Connector Jun 17, 2026 Dec 15, 2020 N/A· v4 7.5 HIGH· v3 4.0 MEDIUM· v2 An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL again...Show more |
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php. |
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow SQL injection attacks if an attacker is able to modify content of particular web pages. |
1Openasset 1Digital Asset Management Jul 9, 2026 Dec 14, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection. |
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if ED...Show more |
1Classroombookings 1Classroombookings Jun 17, 2026 Dec 14, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user. |
1Online Bus Ticket Reservation Project 1Online Bus Ticket Reservation Jun 17, 2026 Dec 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields. |
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter. |
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely. |
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to...Show more |
The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter. |