← Back
CWE-89

20,752 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,752)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
2Emptoris Contract Management
Emptoris Spend Analysis
Jun 17, 2026
Aug 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the att...Show more
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 164067.Show less
1Ibm
2Emptoris Contract Management
Emptoris Spend Analysis
Jun 17, 2026
Aug 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the att...Show more
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 164064.Show less
1Soflyy
1Wp All Import
Nov 21, 2024
Aug 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
1Youphptube
1Youphptube
Jun 17, 2026
Aug 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
1Vanderbilt
1Redcap
Jun 17, 2026
Aug 17, 2019
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessioni...Show more
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.Show less
1Awesomemotive
1Easy Digital Downloads
Feb 7, 2025
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
1Duckdev
1404 To 301
Nov 21, 2024
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
1Themeist
1I Recommend This
Nov 21, 2024
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
1Datainterlock
1Note Press
Nov 21, 2024
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The note-press plugin before 0.1.2 for WordPress has SQL injection.
1Olimometer Project
1Olimometer
Nov 21, 2024
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The olimometer plugin before 2.57 for WordPress has SQL injection.
1Wpbusinessintelligence
1Wp Business Intelligence
Nov 21, 2024
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
1Bestwebsoft
1Visitors Online
Nov 21, 2024
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The visitors-online plugin before 0.4 for WordPress has SQL injection.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can...Show more
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the...Show more
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.Show less
1Givewp
1Givewp
Jun 17, 2026
Aug 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the aff...Show more
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.Show less
1Tipsandtricks Hq
1All In One Wp Security & Firewall
Nov 21, 2024
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
1Tipsandtricks Hq
1All In One Wp Security & Firewall
Nov 21, 2024
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
1Tipsandtricks Hq
1All In One Wp Security & Firewall
Nov 21, 2024
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
1Ninjaforms
1Ninjaforms
Jun 17, 2026
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
1Simplerealtytheme
1Simple Login Log
Nov 21, 2024
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.