← Back
CWE-89

20,748 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,748)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Thephpfactory
1Auction Factory
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
1Scriptzee
1Hotel Booking Engine
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
1Flippa Marketplace Clone Project
1Flippa Marketplace Clone
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
1Education Website Project
1Education Website
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
1Jimtawl Project
1Jimtawl
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
1Arenam
1Amgallery
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
1Healthnode Hospital Management System Project
1Healthnode Hospital Management System
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.
1Open Faculty Evaluation System Project
1Open Faculty Evaluation System
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.
1Open Faculty Evaluation System Project
1Open Faculty Evaluation System
Nov 21, 2024
Jun 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758.
1Dotcms
1Dotcms
Jun 17, 2026
Jun 18, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.
1Sahipro
1Sahi Pro
Nov 21, 2024
Jun 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can be exploited to inject SQL queries and run standard h2 system functions.
1Silverstripe
2Registry
Restfulserver
Jun 17, 2026
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers...Show more
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.Show less
1Apache
1Fineract
Nov 21, 2024
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.
1Apache
1Fineract
Nov 21, 2024
Jun 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.
1Digitaldruid
1Hoteldruid
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
1Digitaldruid
1Hoteldruid
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
1Salesagility
1Suitecrm
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).
1Salesagility
1Suitecrm
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).
1Salesagility
1Suitecrm
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
1Salesagility
1Suitecrm
Jun 17, 2026
Jun 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).