← Back
CWE-89

20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,756)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tuzicms
1Tuzicms
Jun 17, 2026
Sep 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring.
1Typomedia
1Wordpress Meta Robots
Nov 21, 2024
Sep 20, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.
1Trivetechnology
1Wp Stats Dashboard
Nov 21, 2024
Sep 20, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.
1Webmaster Source
1Gocodes
Nov 21, 2024
Sep 20, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.
1Usersultra
1Users Ultra Membership
Nov 21, 2024
Sep 20, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.
1Yejiao
1Tuzicms
Jun 17, 2026
Sep 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.
1Smackcoders
1Ultimate Exporter
Nov 21, 2024
Sep 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
1Terrasoft
1Bpm Online Crm System Sdk
Jun 17, 2026
Sep 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
1Publisure
1Publisure
Jun 17, 2026
Sep 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL injections in userAccFunctions.php functions. Using this, an attacker can access passwor...Show more
An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL injections in userAccFunctions.php functions. Using this, an attacker can access passwords and/or grant access to the user account "user" in order to become "Administrator" (for example).Show less
1Ibm
1Sterling File Gateway
Jun 17, 2026
Sep 16, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information i...Show more
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.Show less
1Egpp
1Sistema Integrado De Gestion Academica
Jun 17, 2026
Sep 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the dat...Show more
In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the database.Show less
1Flamecms Project
1Flamecms
Jun 17, 2026
Sep 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
1Slickquiz Project
1Slickquiz
Jun 17, 2026
Sep 13, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-admin/admin.php?page=slickquiz-scores&id= or /wp-admin/admin.php?page=slickquiz-edit&id= or /wp-admin/...Show more
The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-admin/admin.php?page=slickquiz-scores&id= or /wp-admin/admin.php?page=slickquiz-edit&id= or /wp-admin/admin.php?page=slickquiz-preview&id= URI.Show less
1Firestormplugins
1Fs Shopping Cart
Nov 21, 2024
Sep 13, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.
1Sirv
1Sirv
Nov 21, 2024
Sep 13, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
1Relevanssi
1Relevanssi
Nov 21, 2024
Sep 13, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
1Post Indexer Project
1Post Indexer
Nov 21, 2024
Sep 13, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.
1Wp Kama
1Kama Click Counter
Nov 21, 2024
Sep 13, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
1Zx Csv Upload Project
1Zx Csv Upload
Nov 21, 2024
Sep 13, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
1Podlove
1Podlove Podcast Publisher
Nov 21, 2024
Sep 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.