CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section. |
2Arista Vmware2Velocloud Orchestrator Velocloud OrchestratorJul 28, 2026 Jul 8, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain...Show more |
SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql |
SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql |
SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql |
1Connectwise 1Connectwise Automate Jun 17, 2026 Jul 7, 2020 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. A...Show more |
WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter. |
3Hibernate QuarkusRedhat10Build Of Quarkus Decision ManagerFuse+7 moreJun 17, 2026 Jul 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or G...Show more |
We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page. |
1We Com 1Municipality Portal Cms Jun 17, 2026 Jul 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field. |
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection. |
openSIS through 7.4 allows SQL Injection. |
openSIS before 7.4 allows SQL Injection. |
1Persian Vip Download Script Project 1Persian Vip Download Script Jun 17, 2026 Jul 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter. |
**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6...Show more |
An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, pppoe.php, queues.php, and wifi.php. |
An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and gain client privileges via SQL injection in central/executar_login.php. |
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. |
1Ibm 1Maximo Asset Management Jun 17, 2026 Jun 26, 2020 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end...Show more |
1Turnkeylinux 1Support Incident Tracker Jun 17, 2026 Jun 26, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qb...Show more |