CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 2Sinvr 3 Central Control Server Sinvr 3 Video ServerJun 17, 2026 Mar 10, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an SQL injection vulnerability in its XML-based communication protocol as provided by d...Show more |
controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users to execute arbitrary SQL commands via the 'answer' and 'answers' parameters. |
1Munkireport Project 1Munkireport Jun 17, 2026 Mar 9, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tablequery.php by crafting a special payload on the /datatables/data endpoint. |
JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field. |
JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action. |
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php. |
1Magento 1Advanced Newsletter Nov 21, 2024 Mar 9, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO. |
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. |
1Yubico 1Yubikey One Time Password Validation Server Jun 17, 2026 Mar 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially releva...Show more |
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter. |
5Canonical DebianDjangoproject+2 more5Debian Linux DjangoFedora+2 moreJun 17, 2026 Mar 5, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted toleran...Show more |
1Phpgurukul 1Daily Expense Tracker System Jun 17, 2026 Mar 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in index.php or register.php. The SQL injection allows to dump the MySQL database and to bypass the login...Show more |
Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter t...Show more |
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter. |
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter. |
1Mitel 1Micollab Audio, Web & Video Conferencing Jun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the registeredList.cgi page. A succes...Show more |
1Mitel 1Micollab Audio, Web & Video Conferencing Jun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the session parameter. A successful expl...Show more |
1Eyesofnetwork 1Eyesofnetwork Jun 17, 2026 Feb 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication byp...Show more |
1Ibm 2Business Automation Workflow Business Process ManagerJun 17, 2026 Feb 27, 2020 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 through 19.0.0.3 is vulnerable to SQL injection. A remote attacker could send...Show more |
1Ibm 1Sterling B2b Integrator Jun 17, 2026 Feb 26, 2020 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or d...Show more |