← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Fedoraproject
OpensusePhpmyadmin+1 more
5Backports Sle
FedoraLeap+2 more
Jun 17, 2026
Mar 22, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A mal...Show more
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).Show less
2Linuxfoundation
Pivotal
2Harbor
Vmware Harbor Registry
Jun 17, 2026
Mar 20, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
2Linuxfoundation
Pivotal
2Harbor
Vmware Harbor Registry
Jun 17, 2026
Mar 20, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
1Netsas
1Enigma Network Management Solution
Jun 17, 2026
Mar 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL commands to expose and compromise the web server, expose database tables a...Show more
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL commands to expose and compromise the web server, expose database tables and values, and potentially execute system-based commands as the mysql user. This affects the search_pattern value of the manage_hosts_short.cgi script.Show less
1Cisco
1Sd Wan Firmware
Jun 17, 2026
Mar 19, 2020
N/A· v4
8.1 HIGH· v3
8.5 HIGH· v2
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI im...Show more
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on, or return values from, the underlying database as well as the operating system.Show less
1Logicaldoc
1Logicaldoc
Jun 17, 2026
Mar 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly...Show more
LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database.Show less
1Armorx
1Lisomail
Jun 17, 2026
Mar 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LisoMail, by ArmorX, allows SQL Injections, attackers can access the database without authentication via a URL parameter manipulation.
1R Consortium
1Rmysql
Jun 17, 2026
Mar 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
RMySQL through 0.10.19 allows SQL Injection.
1Salesagility
1Suitecrm
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
1Salesagility
1Suitecrm
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
1Salesagility
1Suitecrm
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
1Salesagility
1Suitecrm
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
1Joomla
1Joomla
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.
1Control Webpanel
1Webpanel
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.
1Dolibarr
1Dolibarr
Jun 17, 2026
Mar 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
1Thoughtbot
1Administrate
Jun 17, 2026
Mar 13, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query. This could present a SQL injection if th...Show more
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query. This could present a SQL injection if the attacker were able to modify the `direction` parameter and bypass ActiveRecord SQL protections. Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0.Show less
1Devome
1Grr
Jun 17, 2026
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query.
1Sapplica
1Sentrifugo
Jun 17, 2026
Mar 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.
1Metagauss
1Registrationmagic
Jun 17, 2026
Mar 12, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id parameter.
1Google
1Android
Jun 17, 2026
Mar 10, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
In query of SmsProvider.java and MmsSmsProvider.java, there is a possible permission bypass due to SQL injection. This could lead to local information disclosure with System execution privileges needed. User interaction...Show more
In query of SmsProvider.java and MmsSmsProvider.java, there is a possible permission bypass due to SQL injection. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143229845Show less