CWE-89
20,750 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,750)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request. |
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability...Show more |
1Saltstack 2Salt 2018 Salt 2019Jun 17, 2026 Jul 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass funct...Show more |
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Cra...Show more |
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the aff...Show more |
1Cisco 1Identity Services Engine Jun 17, 2026 Jul 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries....Show more |
An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could access the backend database via SQL injection. |
1Foliovision 1Fv Flowplayer Video Player Jun 17, 2026 Jul 17, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary...Show more |
1Citrix 2Netscaler Sd Wan Sd WanJun 17, 2026 Jul 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. |
1Solarwinds 1Network Performance Monitor Nov 21, 2024 Jul 16, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter. |
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerabl...Show more |
1Realization 1Concerto Critical Chain Planner Jun 17, 2026 Jul 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter. |
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system...Show more |
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Jul 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. |
Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter. |
An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page. |
An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user. |
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5. |
The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php. |