← Back
CWE-89

20,752 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,752)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Flashlingo Project
1Flashlingo
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
1Social Network Project
1Social Network
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
1Raml Module Builder Project
1Raml Module Builder
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
1Cesnet
1Proxystatistics
Jun 17, 2026
Aug 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
1Youracclaim
1Acclaim
Jun 17, 2026
Aug 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
1Hostosm
1Tasking Manager
Jun 17, 2026
Aug 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
1Email Newsletter Project
1Email Newsletter
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
1Ampache
1Ampache
Jun 17, 2026
Aug 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the da...Show more
An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.Show less
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
1Simplerealtytheme
1Simple Login Log
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
1Search Everything Project
1Search Everything
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.
1Cformsii Project
1Cformsii
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
1Ays Pro
1Photo Gallery
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
1Search Everything Project
1Search Everything
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.
1Codepeople
1Appointment Booking Calendar
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
1Bestwebsoft
1Limit Attempts
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
1Cformsii Project
1Cformsii
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
1Kbpublisher
1Kbpublisher
Jun 17, 2026
Aug 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
1Duplicate Post Project
1Duplicate Post
Nov 21, 2024
Aug 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The duplicate-post plugin before 2.6 for WordPress has SQL injection.
1Codepeople
1Booking Calendar Contact Form
Nov 21, 2024
Aug 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.