CWE-89
20,752 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,752)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Connect Pg Simple Project 1Connect Pg Simple Jun 17, 2026 Aug 26, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 connect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data. |
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php. |
1Xm Online 1Xm^online 2 Common Utils And Endpoints Jun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java. |
1Xm Online 1Xm^online 2 User Account And Authentication Server Jun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key. |
FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php. |
1Reviews Module Project 1Reviews Module Jun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. |
DianoxDragon Hawn before 2019-07-10 allows SQL injection. |
Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php. |
Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php. |
Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php. |
The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php. |
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters. |
HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java. |
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels. |
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature. |
The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java. |
1Webimpacto 1Icommktconnector Jun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php. |
1Compassionuk 1Compassion Switzerland Jun 17, 2026 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py. |
Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java. |
GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm |