← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eyesofnetwork
1Eyesofnetwork
Jun 17, 2026
Oct 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/f...Show more
An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/functions.php file (which is called by login.php).Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
1Victor Cms Project
1Victor Cms
Jun 17, 2026
Oct 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.
1Fireeye
1Email Malware Protection System
Jun 17, 2026
Oct 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.
1Loginizer
1Loginizer
Jun 17, 2026
Oct 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
1Tipsandtricks Hq
1Simple Download Monitor
Jun 17, 2026
Oct 21, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.
1Advantech
1R Seenet
Jun 17, 2026
Oct 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
1Tibco
3Foresight Archive And Retrieval System
Foresight Operational MonitorForesight Transaction Insight
Jun 17, 2026
Oct 20, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIB...Show more
The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection. Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0.Show less
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Oct 20, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or d...Show more
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171733.Show less
1Aptean
1Product Configurator
Jun 17, 2026
Oct 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remote...Show more
An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely.Show less
1Siemens
1Desigo Insight
Jun 17, 2026
Oct 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input validation for some query parameters in a reserved area. This could allow an authenticated attacker to r...Show more
A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input validation for some query parameters in a reserved area. This could allow an authenticated attacker to retrieve data via a content-based blind SQL injection attack.Show less
1Rapid7
1Nexpose
Jun 17, 2026
Oct 14, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low permission level to access resources & make changes they should not have been able to access.
1Evolutionscript
1Helpdeskz
Jun 17, 2026
Oct 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by th...Show more
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Show less
4Debian
FedoraprojectOpensuse+1 more
5Backports Sle
Debian LinuxFedora+2 more
Jun 17, 2026
Oct 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker coul...Show more
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.Show less
1Online Bus Booking System Project
1Online Bus Booking System
Jun 17, 2026
Oct 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
1Glpi Project
1Glpi
Jun 17, 2026
Oct 7, 2020
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SELECT query to reflect sensitive informati...Show more
In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SELECT query to reflect sensitive information such as the current database version, or database user. The most likely scenario for this vulnerability is with someone who has an API account to the system. The issue is patched in version 9.5.2. A proof-of-concept with technical details is available in the linked advisory.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Oct 7, 2020
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulnerability an attacker...Show more
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulnerability an attacker is able to exfiltrate sensitive information like passwords, reset tokens, personal details, and more. The issue is patched in version 9.5.2Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
1Damstratechnology
1Smart Asset
Jun 17, 2026
Oct 2, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.