← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mitel
1Micloud Management Portal
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.
1Prestashop
1Prestashop
Jun 17, 2026
Sep 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. The problem is fixed in 1.7.6.8
1Jdownloads
1Jdownloads
Jun 17, 2026
Sep 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.
1Aveva
1Edna Enterprise Data Historian
Jun 17, 2026
Sep 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthentica...Show more
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.Show less
1Aveva
1Edna Enterprise Data Historian
Jun 17, 2026
Sep 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unaut...Show more
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.Show less
1Aveva
1Edna Enterprise Data Historian
Jun 17, 2026
Sep 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data co...Show more
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstanceName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks.Show less
1Aveva
1Edna Enterprise Data Historian
Jun 17, 2026
Sep 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compr...Show more
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter ClassName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks.Show less
1Aveva
1Edna Enterprise Data Historian
Jun 17, 2026
Sep 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data co...Show more
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstancePath in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks.Show less
1Simple Library Management System Project
1Simple Library Management System
Jul 9, 2026
Sep 22, 2020
N/A· v4
8.4 HIGH· v3
4.6 MEDIUM· v2
Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http://<site>/lms/admin.php.
1Phpgurukul
1Zoo Management System
Jul 9, 2026
Sep 22, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.
1Telestream
2Medius
Sentry
Jun 17, 2026
Sep 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Telestream Tektronix Medius before 10.7.5 and Sentry before 10.7.5 have a SQL injection vulnerability allowing an unauthenticated attacker to dump database contents via the page parameter in a page=login request to index...Show more
Telestream Tektronix Medius before 10.7.5 and Sentry before 10.7.5 have a SQL injection vulnerability allowing an unauthenticated attacker to dump database contents via the page parameter in a page=login request to index.php (aka the server login page).Show less
1Hpe
1Universal Api Framework
Jun 17, 2026
Sep 18, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware...Show more
A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft Hyper-V (VHD).Show less
1Corephp
1Pago Commerce
Jun 17, 2026
Sep 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.
1Google
1Android
Jun 17, 2026
Sep 17, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...Show more
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-132074310Show less
1Google
1Android
Jun 17, 2026
Sep 17, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...Show more
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-140729887Show less
1Flexsolution
1Reset Password
Jun 17, 2026
Sep 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.
1Projectworlds
1House Rental
Jun 17, 2026
Sep 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.
1Ibm
1Maximo Asset Management
Jun 17, 2026
Sep 15, 2020
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the...Show more
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437.Show less
1Recall Products Project
1Recall Products
Jun 17, 2026
Sep 14, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query.
1Hyland
1Onbase
Jun 17, 2026
Sep 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by TestConnection_Local...Show more
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by TestConnection_LocalOrLinkedServer, CreateFilterFriendlyView, or AddWorkViewLinkedServer.Show less