CWE-89
20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,756)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zm Gallery Project 1Zm Gallery Nov 21, 2024 Sep 13, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter. |
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter. |
SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. |
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. |
1Dell 2Rsa Identity Governance And Lifecycle Rsa Via Lifecycle And GovernanceJun 17, 2026 Sep 11, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could...Show more |
1Ibps Online Exam Project 1Ibps Online Exam Nov 21, 2024 Sep 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter. |
1Jtrt Responsive Tables Project 1Jtrt Responsive Tables Nov 21, 2024 Sep 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter. |
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstr...Show more |
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extr...Show more |
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection. |
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter. |
A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page. |
An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compro...Show more |
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. |
1Prophecyinternational 1Snare Central Jun 17, 2026 Aug 29, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter. |
The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066. |
The sharebar plugin before 1.2.2 for WordPress has SQL injection. |
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the...Show more |
The wp-polls plugin before 2.72 for WordPress has SQL injection. |
1Genetechsolutions 1Pie Register Jun 17, 2026 Aug 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. |