← Back
CWE-89

20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,756)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Youphptube
1Youphptube
Jun 17, 2026
Oct 25, 2019
N/A· v4
9.9 CRITICAL· v3
9.3 HIGH· v2
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL...Show more
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and,in certain configuration, access the underlying operating system.Show less
1Zend
1Framework
Nov 21, 2024
Oct 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
1Typestack Class Validator Project
1Typestack Class Validator
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues paramet...Show more
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input. NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product.Show less
1Hotel And Lodge Management System Project
1Hotel And Lodge Management System
Jun 17, 2026
Oct 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Roo...Show more
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.Show less
1Online Grading System Project
1Online Grading System
Jun 17, 2026
Oct 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page...Show more
Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).Show less
1Freshmail
1Freshmail Newsletter
Nov 21, 2024
Oct 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
1Open Emr
1Openemr
Jun 17, 2026
Oct 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstr...Show more
Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.Show less
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL injection.
1Topmeeting
1Topmeeting
Jun 17, 2026
Oct 17, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and userna...Show more
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.Show less
1Wikidsystems
1Two Factor Authentication Enterprise Server
Jun 17, 2026
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter.
1Sequelizejs
1Sequelize
Jun 17, 2026
Oct 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaD...Show more
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.Show less
1Wikidsystems
12fa Enterprise Server
Jun 17, 2026
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPref.jsp key parameter.
1Wikidsystems
1Two Factor Authentication Enterprise Server
Jun 17, 2026
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL...Show more
WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL query constructed in the buildSearchWhereClause function.Show less
1Url Redirect Project
1Url Redirect
Jun 17, 2026
Oct 16, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection.
174cms
174cms
Jun 17, 2026
Oct 15, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauth...Show more
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.Show less
1Dormsystem Project
1Dormsystem
Jun 17, 2026
Oct 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
1Metinfo
1Metinfo
Jun 17, 2026
Oct 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
1Idreamsoft
1Icms
Jun 17, 2026
Oct 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
1K 78
1Broken Link Manager
Nov 21, 2024
Oct 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.