← Back
CWE-89

20,750 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,750)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Metinfo
1Metinfo
Jun 17, 2026
Jul 19, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.
1I Doit
1I Doit
Jun 17, 2026
Jul 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability...Show more
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.Show less
1Saltstack
2Salt 2018
Salt 2019
Jun 17, 2026
Jul 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass funct...Show more
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.Show less
1Techytalk
1Quick Chat
Jun 17, 2026
Jul 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Cra...Show more
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.Show less
1Wpeverest
1Everest Forms
Jun 17, 2026
Jul 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the aff...Show more
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.phpShow less
1Cisco
1Identity Services Engine
Jun 17, 2026
Jul 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries....Show more
A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data. At the time of publication, this vulnerability affected Cisco ISE running software releases 2.6.0 and prior.Show less
1Sertek
1Xpare
Jun 17, 2026
Jul 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could access the backend database via SQL injection.
1Foliovision
1Fv Flowplayer Video Player
Jun 17, 2026
Jul 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary...Show more
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.Show less
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
Jul 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
1Solarwinds
1Network Performance Monitor
Nov 21, 2024
Jul 16, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
1Deepsoft
1Weblibrarian
Jun 17, 2026
Jul 15, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerabl...Show more
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerable to a boolean-based blind sql injection. This function call can be triggered by any user logged-in with at least Volunteer role or manage_circulation capabilities. PoC : /wordpress/wp-admin/admin.php?page=weblib-circulation-desk&orderby=title&order=DESC.Show less
1Realization
1Concerto Critical Chain Planner
Jun 17, 2026
Jul 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.
1Avaya
1Control Manager
Jun 17, 2026
Jul 11, 2019
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system...Show more
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x and 8.0.x versions prior to 8.0.4.0. Unsupported versions not listed here were not evaluated.Show less
1Hidea
1Az Admin
Jun 17, 2026
Jul 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.
4Debian
FedoraprojectOpensuse+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
Jul 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
1Trape Project
1Trape
Jun 17, 2026
Jul 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.
1Hsycms
1Hsycms
Jun 17, 2026
Jul 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page.
1Teclib Edition
1Fields
Jun 17, 2026
Jul 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.
1Contao
1Contao
Jun 17, 2026
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
1Boiteasite
1Rencontre
Jun 17, 2026
Jul 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.