CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Designmasterevents 1Conference Management Jun 17, 2026 Aug 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page. |
1F5 1Big Ip Advanced Firewall Manager Jun 17, 2026 Aug 26, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In versions 15.0.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a vulnerability in the BIG-IP AFM Configuration utility may allow any authenticated BIG-IP user to perform a read-only...Show more |
1Wordpress Poll Project 1Wordpress Poll Jun 17, 2026 Aug 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entir...Show more |
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php. |
2Opensuse Postgresql2Leap PostgresqlJun 17, 2026 Aug 24, 2020 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to...Show more |
1Kabir M Alhasan 1Student Management System Jun 17, 2026 Aug 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". |
1Phpgurukul 1Vehicle Parking Management System Jun 17, 2026 Aug 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". |
1Online Shopping Alphaware Project 1Online Shopping Alphaware Jun 17, 2026 Aug 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters. |
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection. |
An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webservice of the SGLAC web frontend allows an attacker to run arbitrary SQL commands on the SQL Server....Show more |
A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows remote authenticated users to execute arbitrary SQL commands via the exportId parameter. |
A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers to execute arbitrary SQL commands via the TPF_XPAR1 parameter. |
1Thedaylightstudio 1Fuel Cms Jun 17, 2026 Aug 13, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. |
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php. |
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection. |
1Carson Saint 1Saint Security Suite Jun 17, 2026 Aug 10, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database. |
1Carson Saint 1Saint Security Suite Jun 17, 2026 Aug 10, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database. |
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to...Show more |
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or...Show more |
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases. |