← Back
CWE-89

20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,756)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webtechideas
1Wti Like Post
Nov 21, 2024
Oct 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
1Yet Another Stars Rating Project
1Yet Another Stars Rating
Nov 21, 2024
Oct 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter.
1Awesome Filterable Portfolio Project
1Awesome Filterable Portfolio
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.
1Brinidesigner
1Awesome Filterable Portfolio
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter.
1Pinpoint
1Pinpoint Booking System
Nov 21, 2024
Oct 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
1Seo Searchterms Tagging 2 Project
1Seo Searchterms Tagging 2
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms count parameter exploitable via CSRF.
1Caseproof
1Prettylinks
Feb 13, 2025
Oct 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
1Adhouma Cms Project
1Adhouma Cms
Jun 17, 2026
Oct 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
1Awplife
1Contact Form Widget
Jun 17, 2026
Oct 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
1Metinfo
1Metinfo
Jun 17, 2026
Oct 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.
1Metinfo
1Metinfo
Jun 17, 2026
Oct 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from the web UI into the...Show more
An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from the web UI into the database.Show less
1Netreo
1Omnicenter
Jun 17, 2026
Oct 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read...Show more
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read sensitive information from the database used by the application.Show less
1Otcms
1Otcms
Jun 17, 2026
Oct 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a...Show more
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a .php file.Show less
1Knexjs
1Knex
Jun 17, 2026
Oct 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
1Vbulletin
1Vbulletin
Jun 17, 2026
Oct 8, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
1Centreon
1Centreon Web
Nov 21, 2024
Oct 8, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.
1Centreon
1Centreon Web
Nov 21, 2024
Oct 8, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user.