← Back
CWE-89

20,748 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,748)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mlmsoftwarez
10Add Clicking Mlm Software
Autopool Mlm SoftwareBidding Mlm Software+7 more
Nov 21, 2024
May 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyo...Show more
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter, the member/tree.php pid parameter, or the member/downline.php m_id parameter.Show less
1Abantecart
1Abantecart
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php an...Show more
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.Show less
1Vtiger
1Vtiger Crm
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
1Exponentcms
1Exponent Cms
Nov 21, 2024
May 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.
110web
1Form Maker
Jun 17, 2026
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /model...Show more
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.Show less
1Computrols
1Computrols Building Automation Software
Jun 17, 2026
May 23, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
1Exponentcms
1Exponent Cms
Nov 21, 2024
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.
1Zohocorp
1Manageengine Opmanager
Nov 21, 2024
May 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
1Zohocorp
1Manageengine Applications Manager
Nov 21, 2024
May 23, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
1Schneider Electric
1U.motion Builder
Jun 17, 2026
May 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
1Nagios
1Nagios Xi
Jun 17, 2026
May 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to...Show more
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any valid injection that can be done with the variable provided, and while the username value being passed does get used in a SQL query, it is passed through SQL escaping functions when creating the call. The vendor tried re-creating the issue with no luckShow less
1Commsy
1Commsy
Jun 17, 2026
May 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CommSy through 8.6.5 has SQL Injection via the cid parameter. This is fixed in 9.2.
1Ucms Project
1Ucms
Jun 17, 2026
May 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.
1Wpbookingsystem
1Wp Booking System
Jun 17, 2026
May 20, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
1Vtiger
1Vtiger Crm
Jun 17, 2026
May 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
1Cybozu
1Garoon
Jun 17, 2026
May 17, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.
1Open Emr
1Openemr
Nov 21, 2024
May 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
1Open Emr
1Openemr
Nov 21, 2024
May 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
1Sensiolabs
1Symfony
Jun 17, 2026
May 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not v...Show more
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.Show less
2Drupal
Sensiolabs
2Drupal
Symfony
Jun 17, 2026
May 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is relate...Show more
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.Show less