CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adminpanel Project 1Adminpanel Jun 17, 2026 May 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter. |
1Cisco 1Prime Collaboration Provisioning Jun 17, 2026 May 22, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerabi...Show more |
1Strangerstudios 1Paid Memberships Pro Jun 17, 2026 May 20, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. |
1Rockwellautomation 5Eds Subsystem RslinxRslinx Enterprise+2 moreJun 17, 2026 May 20, 2020 N/A· v4 8.2 HIGH· v3 4.8 MEDIUM· v2 Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Ve...Show more |
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318. |
1Mikrotik Router Monitoring System Project 1Mikrotik Router Monitoring System Jun 17, 2026 May 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community. |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 May 12, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify database objects, or exec...Show more |
1Sap 3Master Data Governance (s4core) Master Data Governance (s4fnd)Master Data Governance (sap Bs Fnd)Jun 17, 2026 May 12, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, lea...Show more |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 May 12, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevate privileges of users in the system, leading to SQL Injection. |
Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter. |
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary S...Show more |
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands. |
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. |
1Blaauwproducts 1Remote Kiln Control Jun 17, 2026 May 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database. |
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6. |
1Internet Formation 1Wp Advanced Search Jun 17, 2026 May 5, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation. |
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection |
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections. |
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php m...Show more |
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250. |