CWE-89
20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,756)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable. |
1Yet Another Stars Rating Project 1Yet Another Stars Rating Nov 21, 2024 Oct 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter. |
1Awesome Filterable Portfolio Project 1Awesome Filterable Portfolio Nov 21, 2024 Oct 10, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter. |
1Brinidesigner 1Awesome Filterable Portfolio Nov 21, 2024 Oct 10, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter. |
1Pinpoint 1Pinpoint Booking System Nov 21, 2024 Oct 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter. |
1Seo Searchterms Tagging 2 Project 1Seo Searchterms Tagging 2 Nov 21, 2024 Oct 10, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms count parameter exploitable via CSRF. |
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter. |
1Adhouma Cms Project 1Adhouma Cms Jun 17, 2026 Oct 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter. |
1Awplife 1Contact Form Widget Jun 17, 2026 Oct 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php. |
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter. |
An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997. |
An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from the web UI into the...Show more |
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read...Show more |
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a...Show more |
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB. |
vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter. |
makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter. |
img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter. |
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user. |
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user. |