← Back
CWE-89

20,757 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,757)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
1Global Management System
Jun 17, 2026
Dec 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1.
1Mfscripts
1Yetishare
Jun 17, 2026
Dec 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically...Show more
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.Show less
1Mfscripts
1Yetishare
Jun 17, 2026
Dec 30, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker...Show more
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.Show less
1Tms Outsource
1Wpdatatables Lite
Jun 17, 2026
Dec 26, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
1Equinoxce
1Control Expert
Jun 17, 2026
Dec 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code.
1Joomsky
1Js Jobs
Jun 17, 2026
Dec 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child par...Show more
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter.Show less
1Sonicwall
1Sma 100 Firmware
Jun 17, 2026
Dec 19, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
1Apple
6Icloud
Iphone OsItunes+3 more
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously c...Show more
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. A maliciously crafted SQL query may lead to arbitrary code execution.Show less
1Joomla
1Joomla
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
1Sonicwall
1Sma 100 Firmware
Aug 12, 2026
Dec 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.
1Typo3
1Typo3
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation r...Show more
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.Show less
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intesync Solismed 3.3sp has SQL Injection.
1Octeth
1Oempro
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
1Dbd\
1\
Nov 21, 2024
Dec 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in DBD::PgPP 0.05 and earlier
1Zabbix
1Zabbix
Nov 21, 2024
Dec 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Dec 11, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Dec 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
1Accentis
1Content Resource Management System
Nov 21, 2024
Dec 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.
1Titool
1Printmonitor
Jun 17, 2026
Dec 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi.
2Debian
Minidlna Project
2Debian Linux
Minidlna
Nov 21, 2024
Dec 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0