← Back
CWE-89

20,757 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,757)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dejavuprotech
1Crescendo Sales Crm
Nov 21, 2024
Jan 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Déjà Vu Crescendo Sales CRM has remote SQL Injection
3Debian
PhpmyadminSuse
3Debian Linux
PhpmyadminSuse Linux Enterprise Server
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker mus...Show more
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.Show less
1Soplanning
1Soplanning
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.
1Plixer
1Scrutinizer Netflow & Sflow Analyzer
Nov 21, 2024
Jan 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands vi...Show more
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to cgi-bin/scrut_fa_exclusions.cgi, (2) getPermissionsAndPreferences parameter to cgi-bin/login.cgi, or (3) possibly certain parameters to d4d/alarms.php as demonstrated by the search_str parameter.Show less
1Ibm
1Jazz Reporting Service
Jun 17, 2026
Jan 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the bac...Show more
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.Show less
1Imperva
1Securesphere Web Application Firewall
Nov 21, 2024
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
1Small Crm Project
1Small Crm
Jun 17, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.
1Phpgurukul
1Hostel Management System
Jun 17, 2026
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
1Icegram
1Email Subscribers & Newsletters
Jun 17, 2026
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
1Opservices
1Opmon
Jun 17, 2026
Jan 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.
1Phpgurukul
1Dairy Farm Shop Management System
Jun 17, 2026
Jan 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName param...Show more
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.Show less
1Soplanning
1Soplanning
Nov 21, 2024
Jan 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.
1Gilacms
1Gila Cms
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit th...Show more
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit th...Show more
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.Show less
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jan 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information...Show more
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.Show less
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Jun 17, 2026
Jan 5, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection.
1Loadedcommerce
1Loaded7
Nov 21, 2024
Jan 3, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks...Show more
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.Show less
1Jomres
1Jomres
Nov 21, 2024
Jan 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to execute arbitrary SQL commands via the id parameter in...Show more
SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to execute arbitrary SQL commands via the id parameter in an editProfile action to administrator/index.php.Show less
1Zenphoto
1Zenphoto
Nov 21, 2024
Dec 31, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.