← Back
CWE-89

20,752 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,752)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adenion
1Blog2social
Jun 17, 2026
Aug 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
1Nextcloud
1Nextcloud
Jun 17, 2026
Jul 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.
1Oxid Esales
1Eshop
Jun 17, 2026
Jul 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction...Show more
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.Show less
110web
1Photo Gallery
Jun 17, 2026
Jul 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the aff...Show more
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.Show less
2Openstack
Redhat
2Ironic Inspector
Openstack
Jun 17, 2026
Jul 30, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This fu...Show more
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.Show less
1Apache
1Virtual Computing Lab
Nov 21, 2024
Jul 29, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to thi...Show more
Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.Show less
1Apache
1Virtual Computing Lab
Nov 21, 2024
Jul 29, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows f...Show more
Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.Show less
1Vsourz
1Advanced Cf7 Db
Jun 17, 2026
Jul 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands...Show more
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.Show less
1Eclass
1Eclass Ip
Jun 17, 2026
Jul 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.
1Opensns
1Opensns
Jun 17, 2026
Jul 25, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OpenSNS v6.1.0 allows SQL Injection via the index.php?s=/ucenter/Config/ uid parameter because of the getNeedQueryData function in Application/Common/Model/UserModel.class.php.
1Marginalia Project
1Marginalia
Jun 17, 2026
Jul 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component th...Show more
marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is: Hacker inputs a SQL to a vulnerable vector(header, http parameter, etc). The fixed version is: 1.6.Show less
1Jeesite
1Jeesite
Jun 17, 2026
Jul 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByBusinessId() function in src/main/java/com.thinkgem.jeesite/modules/act/ActDao.java has SQL...Show more
Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByBusinessId() function in src/main/java/com.thinkgem.jeesite/modules/act/ActDao.java has SQL Injection vulnerability. The attack vector is: network connectivity,authenticated. The fixed version is: 4.0 and later.Show less
1Ajdg
1Adrotate
Jun 17, 2026
Jul 23, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.
1Zzcms
1Zzcms
Jun 17, 2026
Jul 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.
1Zzcms
1Zzcms
Jun 17, 2026
Jul 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.
1Onionbuzz
1Onionbuzz
Jun 17, 2026
Jul 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to...Show more
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.Show less
1Onionbuzz
1Onionbuzz
Jun 17, 2026
Jul 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a...Show more
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.Show less
1Icegram
1Email Subscribers & Newsletters
Jun 17, 2026
Jul 19, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL...Show more
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.Show less
1H3c
1H3cloud Os
Jun 17, 2026
Jul 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter.