← Back
CWE-89

20,756 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,756)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zm Gallery Project
1Zm Gallery
Nov 21, 2024
Sep 13, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
1Xtremelocator
1Xtremelocator
Nov 21, 2024
Sep 13, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
1Panasonic
1Video Insight Vms
Jun 17, 2026
Sep 12, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
1Cybozu
1Garoon
Jun 17, 2026
Sep 12, 2019
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
1Dell
2Rsa Identity Governance And Lifecycle
Rsa Via Lifecycle And Governance
Jun 17, 2026
Sep 11, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could...Show more
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the data by supplying specially crafted input data to the affected application.Show less
1Ibps Online Exam Project
1Ibps Online Exam
Nov 21, 2024
Sep 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.
1Jtrt Responsive Tables Project
1Jtrt Responsive Tables
Nov 21, 2024
Sep 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter.
1Librenms
1Librenms
Jun 17, 2026
Sep 9, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstr...Show more
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.php?debug=1&term= request.Show less
1Librenms
1Librenms
Jun 17, 2026
Sep 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extr...Show more
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter.Show less
1Jobberbase
1Jobberbase
Jun 17, 2026
Sep 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.
110web
1Photo Gallery
Jun 17, 2026
Sep 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
1Mapsolutions
1Intramaps
Jun 17, 2026
Sep 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page.
1Epignosishq
1Efront Lms
Jun 17, 2026
Sep 5, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compro...Show more
An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compromise. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
1Wpbrigade
1Loginpress
Jun 17, 2026
Sep 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
1Prophecyinternational
1Snare Central
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter.
1Tri
1Gigpress
Nov 21, 2024
Aug 28, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066.
1Sharebar Project
1Sharebar
Nov 21, 2024
Aug 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
1Imagely
1Nextgen Gallery
Jun 17, 2026
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the...Show more
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.Show less
1Wp Polls Project
1Wp Polls
Nov 21, 2024
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-polls plugin before 2.72 for WordPress has SQL injection.
1Genetechsolutions
1Pie Register
Jun 17, 2026
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.