← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Designmasterevents
1Conference Management
Jun 17, 2026
Aug 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
1F5
1Big Ip Advanced Firewall Manager
Jun 17, 2026
Aug 26, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In versions 15.0.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a vulnerability in the BIG-IP AFM Configuration utility may allow any authenticated BIG-IP user to perform a read-only...Show more
In versions 15.0.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a vulnerability in the BIG-IP AFM Configuration utility may allow any authenticated BIG-IP user to perform a read-only blind SQL injection attack.Show less
1Wordpress Poll Project
1Wordpress Poll
Jun 17, 2026
Aug 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entir...Show more
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.Show less
1Os4ed
1Opensis
Jun 17, 2026
Aug 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.
2Opensuse
Postgresql
2Leap
Postgresql
Jun 17, 2026
Aug 24, 2020
N/A· v4
7.1 HIGH· v3
4.6 MEDIUM· v2
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to...Show more
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.Show less
1Kabir M Alhasan
1Student Management System
Jun 17, 2026
Aug 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
1Phpgurukul
1Vehicle Parking Management System
Jun 17, 2026
Aug 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
1Online Shopping Alphaware Project
1Online Shopping Alphaware
Jun 17, 2026
Aug 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
1Citrix
1Xenmobile Server
Jun 17, 2026
Aug 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.
1Dbsoft
1Sglac
Jun 17, 2026
Aug 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webservice of the SGLAC web frontend allows an attacker to run arbitrary SQL commands on the SQL Server....Show more
An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webservice of the SGLAC web frontend allows an attacker to run arbitrary SQL commands on the SQL Server. Command execution can be easily achieved by using the xp_cmdshell stored procedure.Show less
1Loway
1Queuemetrics
Jun 17, 2026
Aug 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows remote authenticated users to execute arbitrary SQL commands via the exportId parameter.
1Loway
1Queuemetrics
Jun 17, 2026
Aug 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers to execute arbitrary SQL commands via the TPF_XPAR1 parameter.
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Aug 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
1Articatech
1Web Proxy
Jun 17, 2026
Aug 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Aug 12, 2020
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
1Carson Saint
1Saint Security Suite
Jun 17, 2026
Aug 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database.
1Carson Saint
1Saint Security Suite
Jun 17, 2026
Aug 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database.
1Frappe
1Erpnext
Jun 17, 2026
Aug 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to...Show more
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Cayintech
1Xpost
Jun 17, 2026
Aug 6, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or...Show more
CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.Show less
1Apache
1Skywalking
Jun 17, 2026
Aug 5, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.