← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Abb
2Symphony + Historian
Symphony + Operations
Jun 17, 2026
Dec 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shu...Show more
In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. This can lead to a loss of confidentiality and data integrity or even affect the product behavior and its availability.Show less
1Phpgurukul
1Online Marriage Registration System
Jun 17, 2026
Dec 21, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
1Bilanc
1Bilanc
Jun 17, 2026
Dec 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.
1Seacms
1Seacms
Jun 17, 2026
Dec 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
1Yunyecms
1Yunyecms
Jun 17, 2026
Dec 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.
1Egavilanmedia
1Ecm Address Book
Jul 9, 2026
Dec 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
1Weiphp
1Weiphp
Jun 17, 2026
Dec 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
1Mitel
1Micollab
Jun 17, 2026
Dec 18, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.
1Spotweb Project
1Spotweb
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
1Keysight
1Keysight Database Connector
Jun 17, 2026
Dec 15, 2020
N/A· v4
7.5 HIGH· v3
4.0 MEDIUM· v2
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL again...Show more
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.Show less
1Newpk Project
1Newpk
Jun 17, 2026
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
1Siemens
1Xhq
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow SQL injection attacks if an attacker is able to modify content of particular web pages.
1Openasset
1Digital Asset Management
Jul 9, 2026
Dec 14, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
1Gallagher
1Command Centre
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if ED...Show more
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if EDI is configured to import data from this database. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); 8.00 versions prior to 8.00.1228(MR6); version 7.90 and prior versions.Show less
1Classroombookings
1Classroombookings
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
1Online Bus Ticket Reservation Project
1Online Bus Ticket Reservation
Jun 17, 2026
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
1Phpshe
1Phpshe
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
1Sophos
1Cyberoamos
Aug 15, 2026
Dec 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
1Processmaker
1Processmaker
Jun 17, 2026
Dec 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to...Show more
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.Show less
1Divebook Project
1Divebook
Jun 17, 2026
Dec 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter.