← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Learndash
1Learndash
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
1Leantime
1Leantime
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and av...Show more
Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and availability of the site. Attackers can exfiltrate data like the users' and administrators' password hashes, modify data, or drop tables. The unescaped parameter is "searchUsers" when sending a POST request to "/tickets/showKanban" with a valid session. In the code, the parameter is named "users" in class.tickets.php. This issue is fixed in versions 2.0.15 and 2.1.0 beta 3.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Mar 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover us...Show more
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Mar 30, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, thro...Show more
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Mar 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and d...Show more
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.Show less
1Odata4j Project
1Odata4j
Nov 21, 2024
Mar 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
1Odata4j Project
1Odata4j
Nov 21, 2024
Mar 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
1Weberp
1Weberp
Jun 17, 2026
Mar 30, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
1Custom Searchable Data Entry System Project
1Custom Searchable Data Entry System
Jun 17, 2026
Mar 27, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued.
1Unisoon
1Ultralog Express Firmware
Jun 17, 2026
Mar 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
1Microfocus
1Service Manager Automation
Jun 17, 2026
Mar 26, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutr...Show more
An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead to the product being vulnerable to SQL injection.Show less
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is SVE-2018-13452 (March 2019).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Story Video Editor Content Provider. The Samsung ID is SVE-2019-14062 (July 2019).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Gear VR Service Content Provider. The Samsung ID is SVE-2019-14058 (July 2019).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-2019-14365 (August 2019).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Wi-Fi history Content Provider. The Samsung ID is SVE-2019-14061 (August 2019).
1Google
1Android
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the RCS Content Provider. The Samsung IDs are SVE-2019-14059, SVE-2019-14685 (August 2019).
1Grandstream
1Ucm6200 Firmware
Jun 17, 2026
Mar 23, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions...Show more
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.Show less
5Debian
FedoraprojectOpensuse+2 more
6Backports Sle
Debian LinuxFedora+3 more
Jun 17, 2026
Mar 22, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.ph...Show more
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.Show less
5Debian
FedoraprojectOpensuse+2 more
6Backports Sle
Debian LinuxFedora+3 more
Jun 17, 2026
Mar 22, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/cla...Show more
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be performed if a user attempts certain search operations on the malicious database or table.Show less