CWE-89
20,752 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,752)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Emptoris Contract Management Emptoris Spend AnalysisJun 17, 2026 Aug 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the att...Show more |
1Ibm 2Emptoris Contract Management Emptoris Spend AnalysisJun 17, 2026 Aug 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the att...Show more |
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. |
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection. |
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessioni...Show more |
1Awesomemotive 1Easy Digital Downloads Feb 7, 2025 Aug 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection. |
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection. |
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. |
The note-press plugin before 0.1.2 for WordPress has SQL injection. |
1Olimometer Project 1Olimometer Nov 21, 2024 Aug 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The olimometer plugin before 2.57 for WordPress has SQL injection. |
1Wpbusinessintelligence 1Wp Business Intelligence Nov 21, 2024 Aug 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection. |
1Bestwebsoft 1Visitors Online Nov 21, 2024 Aug 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The visitors-online plugin before 0.4 for WordPress has SQL injection. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Aug 16, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Aug 16, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the...Show more |
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the aff...Show more |
1Tipsandtricks Hq 1All In One Wp Security & Firewall Nov 21, 2024 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. |
1Tipsandtricks Hq 1All In One Wp Security & Firewall Nov 21, 2024 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. |
1Tipsandtricks Hq 1All In One Wp Security & Firewall Nov 21, 2024 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. |
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. |
1Simplerealtytheme 1Simple Login Log Nov 21, 2024 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The simple-login-log plugin before 1.1.2 for WordPress has SQL injection. |