← Back
CWE-89

20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,756)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Oct 2, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device....Show more
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Oct 2, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device....Show more
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.Show less
1Netgear
1Srx5308 Firmware
Jun 17, 2026
Sep 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user account.
1Idcos
1Cloudboot
Jun 17, 2026
Sep 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI.
1Metinfo
1Metinfo
Jun 17, 2026
Sep 30, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
1Metinfo
1Metinfo
Jun 17, 2026
Sep 30, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
1Ebrigade
1Ebrigade
Jun 17, 2026
Sep 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.
1Ebrigade
1Ebrigade
Jun 17, 2026
Sep 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
eBrigade before 5.0 has evenements.php cid SQL Injection.
1Ebrigade
1Ebrigade
Jun 17, 2026
Sep 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.
1Inoideas
1Inoerp
Jun 17, 2026
Sep 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
1Pressified
1Sendpress
Nov 21, 2024
Sep 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.
1Unitegallery
1Unite Gallery Lite
Nov 21, 2024
Sep 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
1Efficientscripts
1Microblog Poster
Nov 21, 2024
Sep 26, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=microblogposter.php account_id parameter.
1Centreon
1Centreon
Jun 17, 2026
Sep 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.
1Ipswitch
1Moveit Transfer
Jun 17, 2026
Sep 24, 2019
N/A· v4
9.4 CRITICAL· v3
7.5 HIGH· v2
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the data...Show more
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or may be able to alter the database via the REST API, aka SQL Injection.Show less
1Phpipam
1Phpipam
Jun 17, 2026
Sep 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
1Phpipam
1Phpipam
Jun 17, 2026
Sep 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
1Phpipam
1Phpipam
Jun 17, 2026
Sep 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
1Phpipam
1Phpipam
Jun 17, 2026
Sep 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
1Phpipam
1Phpipam
Jun 17, 2026
Sep 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.