CWE-89
20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,756)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL...Show more |
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter. |
1Typestack Class Validator Project 1Typestack Class Validator Jun 17, 2026 Oct 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues paramet...Show more |
1Hotel And Lodge Management System Project 1Hotel And Lodge Management System Jun 17, 2026 Oct 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Roo...Show more |
1Online Grading System Project 1Online Grading System Jun 17, 2026 Oct 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page...Show more |
1Freshmail 1Freshmail Newsletter Nov 21, 2024 Oct 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring. |
Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstr...Show more |
In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL injection. |
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and userna...Show more |
1Wikidsystems 1Two Factor Authentication Enterprise Server Jun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter. |
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaD...Show more |
1Wikidsystems 12fa Enterprise Server Jun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPref.jsp key parameter. |
1Wikidsystems 1Two Factor Authentication Enterprise Server Jun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL...Show more |
1Url Redirect Project 1Url Redirect Jun 17, 2026 Oct 16, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection. |
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Oct 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauth...Show more |
1Dormsystem Project 1Dormsystem Jun 17, 2026 Oct 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 tonyy dormsystem through 1.3 allows SQL Injection in admin.php. |
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI. |
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload. |
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter. |