CWE-89
20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,756)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring. |
1Typomedia 1Wordpress Meta Robots Nov 21, 2024 Sep 20, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection. |
1Trivetechnology 1Wp Stats Dashboard Nov 21, 2024 Sep 20, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection. |
The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection. |
1Usersultra 1Users Ultra Membership Nov 21, 2024 Sep 20, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action. |
App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring. |
1Smackcoders 1Ultimate Exporter Nov 21, 2024 Sep 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. |
1Terrasoft 1Bpm Online Crm System Sdk Jun 17, 2026 Sep 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter. |
An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL injections in userAccFunctions.php functions. Using this, an attacker can access passwor...Show more |
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information i...Show more |
1Egpp 1Sistema Integrado De Gestion Academica Jun 17, 2026 Sep 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the dat...Show more |
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. |
The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-admin/admin.php?page=slickquiz-scores&id= or /wp-admin/admin.php?page=slickquiz-edit&id= or /wp-admin/...Show more |
1Firestormplugins 1Fs Shopping Cart Nov 21, 2024 Sep 13, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter. |
The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter. |
The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization. |
1Post Indexer Project 1Post Indexer Nov 21, 2024 Sep 13, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin. |
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter. |
1Zx Csv Upload Project 1Zx Csv Upload Nov 21, 2024 Sep 13, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter. |
1Podlove 1Podlove Podcast Publisher Nov 21, 2024 Sep 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF. |