← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Iot Field Network Director
Jun 17, 2026
Nov 18, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-end database of an affected device. The vulnerability is due to insuffici...Show more
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-end database of an affected device. The vulnerability is due to insufficient input validation of REST API requests that are made to an affected device. An attacker could exploit this vulnerability by crafting malicious API requests to the affected device. A successful exploit could allow the attacker to gain access to the back-end database of the affected device.Show less
1Cxuu
1Cxuucms
Jun 17, 2026
Nov 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.
1Water Billing System Project
1Water Billing System
Jun 17, 2026
Nov 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.
1Simple Grocery Store Sales And Inventory Sales Project
1Simple Grocery Store Sales And Inventory System
Jun 17, 2026
Nov 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in...Show more
An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.Show less
1Online Clothing Store Project
1Online Clothing Store
Jun 17, 2026
Nov 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.
1Fastadmin
1Fastadmin
Jun 17, 2026
Nov 17, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Nov 16, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attack...Show more
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 186091.Show less
1Ibm
1Sterling File Gateway
Jun 17, 2026
Nov 16, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, mo...Show more
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.Show less
1Phpgurukul
1User Registration & Login And User Management System
Jun 17, 2026
Nov 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 16, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.
1Riken
1Xoonips
Jun 17, 2026
Nov 16, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
2Debian
Postgresql
2Debian Linux
Postgresql
Jun 17, 2026
Nov 16, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can exec...Show more
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
1Fastadmin Tp6 Project
1Fastadmin Tp6
Jun 17, 2026
Nov 13, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can be passed for SQL injection.
1Resourcexpress
1Meeting Monitor
Jun 17, 2026
Nov 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure.
1Sapplica
1Sentrifugo
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetails/edit/userid/2. In this POST request, "employeeNumId" parameter is affected by SQLi vulnerability....Show more
In Sentrifugo 3.2, admin can edit employee's informations via this endpoint --> /sentrifugo/index.php/empadditionaldetails/edit/userid/2. In this POST request, "employeeNumId" parameter is affected by SQLi vulnerability. Attacker can inject SQL commands into query, read data from database or write data into the database.Show less
1Goodlayers
1Good Learning Management System
Jun 17, 2026
Nov 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_l...Show more
An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.Show less
1Magento
1Magento
Jun 17, 2026
Nov 9, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permi...Show more
Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.Show less
1Web Audimex
1Audimexee
Jun 17, 2026
Nov 5, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arbitrary SQL commands via the object_path parameter.
1Qnap
1Music Station
Nov 21, 2024
Nov 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versio...Show more
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.Show less
1Pimcore
1Pimcore
Jun 17, 2026
Oct 30, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input...Show more
The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input in the relationIds parameter as demonstrated by the following request: http://vulnerable.pimcore.example/admin/classificationstore/relations?relationIds=[{"keyId"%3a"''","groupId"%3a"'asd'))+or+1%3d1+union+(select+1,2,3,4,5,6,name,8,password,'',11,12,'',14+from+users)+--+"}]Show less