← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phplist
1Phplist
Jun 17, 2026
Jul 8, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
2Arista
Vmware
2Velocloud Orchestrator
Velocloud Orchestrator
Jul 28, 2026
Jul 8, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain...Show more
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.Show less
1Phpzag
1Phpzag
Jun 17, 2026
Jul 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
1Phpzag
1Phpzag
Jun 17, 2026
Jul 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
1Phpzag
1Phpzag
Jun 17, 2026
Jul 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql
1Connectwise
1Connectwise Automate
Jun 17, 2026
Jul 7, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. A...Show more
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name with little validation, the table name can be modified to allow arbitrary update commands to be run. Usage of other SQL injection techniques such as timing attacks, it is possible to perform full data extraction as well. Patched in 2020.7 and in a hotfix for 2019.12.Show less
1Webchess Project
1Webchess
Jun 17, 2026
Jul 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.
3Hibernate
QuarkusRedhat
10Build Of Quarkus
Decision ManagerFuse+7 more
Jun 17, 2026
Jul 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or G...Show more
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.Show less
1We Com
1Opendata Cms
Jun 17, 2026
Jul 5, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.
1We Com
1Municipality Portal Cms
Jun 17, 2026
Jul 5, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.
1Ithemes
1Paypal Pro
Jun 17, 2026
Jul 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
1Os4ed
1Opensis
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
openSIS through 7.4 allows SQL Injection.
1Os4ed
1Opensis
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
openSIS before 7.4 allows SQL Injection.
1Persian Vip Download Script Project
1Persian Vip Download Script
Jun 17, 2026
Jul 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
1Apache
1Skywalking
Jun 17, 2026
Jun 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6...Show more
**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use the appropriate way to set SQL parameters.Show less
1Mk Auth
1Mk Auth
Jun 17, 2026
Jun 29, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, pppoe.php, queues.php, and wifi.php.
1Mk Auth
1Mk Auth
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and gain client privileges via SQL injection in central/executar_login.php.
1Nexos Project
1Nexos
Jun 17, 2026
Jun 28, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
1Ibm
1Maximo Asset Management
Jun 17, 2026
Jun 26, 2020
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end...Show more
IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.Show less
1Turnkeylinux
1Support Incident Tracker
Jun 17, 2026
Jun 26, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qb...Show more
Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.Show less