← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adminpanel Project
1Adminpanel
Jun 17, 2026
May 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
1Cisco
1Prime Collaboration Provisioning
Jun 17, 2026
May 22, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerabi...Show more
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates user input for specific SQL queries. An attacker could exploit this vulnerability by authenticating to the application with valid administrative credentials and sending malicious requests to an affected system. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, or delete information from the database that they are not authorized to delete.Show less
1Strangerstudios
1Paid Memberships Pro
Jun 17, 2026
May 20, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
1Rockwellautomation
5Eds Subsystem
RslinxRslinx Enterprise+2 more
Jun 17, 2026
May 20, 2020
N/A· v4
8.2 HIGH· v3
4.8 MEDIUM· v2
Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Ve...Show more
Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Version 28.00.00 and prior, Studio 5000 Logix Designer software: Version 32 and prior) is vulnerable.The EDS subsystem does not provide adequate input sanitation, which may allow an attacker to craft specialized EDS files to inject SQL queries and manipulate the database storing the EDS files. This can lead to denial-of-service conditions.Show less
1Ibm
1I
Jun 17, 2026
May 17, 2020
N/A· v4
3.3 LOW· v3
1.9 LOW· v2
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.
1Mikrotik Router Monitoring System Project
1Mikrotik Router Monitoring System
Jun 17, 2026
May 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.
1Sap
1Adaptive Server Enterprise
Jun 17, 2026
May 12, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify database objects, or exec...Show more
Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify database objects, or execute commands they are not otherwise authorized to execute, leading to SQL Injection.Show less
1Sap
3Master Data Governance (s4core)
Master Data Governance (s4fnd)Master Data Governance (sap Bs Fnd)
Jun 17, 2026
May 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, lea...Show more
The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.Show less
1Sap
1Adaptive Server Enterprise
Jun 17, 2026
May 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevate privileges of users in the system, leading to SQL Injection.
1Solis
1Gnuteca
Jun 17, 2026
May 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter.
1Idangero
1Chop Slider
Jun 17, 2026
May 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary S...Show more
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.Show less
1Advantech
1Webaccess
Jun 17, 2026
May 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.
1Vbulletin
1Vbulletin
Jun 17, 2026
May 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
1Blaauwproducts
1Remote Kiln Control
Jun 17, 2026
May 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.
1Glpi Project
1Glpi
Jun 17, 2026
May 5, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6.
1Internet Formation
1Wp Advanced Search
Jun 17, 2026
May 5, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
1Thimpress
1Learnpress
Jun 17, 2026
Apr 30, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
1Opmantek
1Open Audit
Jun 17, 2026
Apr 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.
1Php Fusion
1Php Fusion
Jun 17, 2026
Apr 29, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php m...Show more
PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in the SQL query.Show less
1Ivanti
1Avalanche
Jun 17, 2026
Apr 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.