← Back
CWE-89

20,745 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,745)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Doorgets
1Doorgets Cms
Jun 17, 2026
Apr 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php. A remote normal registered user could exploit the vulnerability to obtain database sensitive information.
1Polarisft
1Intellect Core Banking
Nov 21, 2024
Apr 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /references/refsuppu.jsp and /references/refb...Show more
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /references/refsuppu.jsp and /references/refbranu.jsp is mishandled before being used in SQL queries, allowing SQL injection with an authenticated session.Show less
1Aikcms
1Aikcms
Jun 17, 2026
Apr 27, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in AikCms v2.0. There is a SQL Injection vulnerability via $_GET['del'], as demonstrated by an admin/page/system/nav.php?del= URI.
1Mitel
1Cmg Suite
Nov 21, 2024
Apr 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploi...Show more
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.Show less
1Mitel
1Cmg Suite
Nov 21, 2024
Apr 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful ex...Show more
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.Show less
1Contao
1Contao Cms
Nov 21, 2024
Apr 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
1Sem Cms
1Semcms
Jun 17, 2026
Apr 25, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete.
1Deltek
1Vision
Nov 21, 2024
Apr 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of...Show more
Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of SQL statements and other content being sent to the server. Client HTTP calls can be manipulated by one of several means to execute arbitrary SQL statements (similar to SQLi) or possibly have unspecified other impact via this custom protocol. To perform these attacks an authenticated session is first required. In some cases client calls are obfuscated by encryption, which can be bypassed due to hard-coded keys and an insecure key rotation protocol. Impacts may include remote code execution in some deployments; however, the vendor states that this cannot occur when the installation documentation is heeded.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 23, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious...Show more
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.Show less
1Whatsns
1Whatsns
Jun 17, 2026
Apr 22, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
whatsns 4.0 allows index.php?admin_category/remove.html cid[] SQL injection.
1Whatsns
1Whatsns
Jun 17, 2026
Apr 22, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
whatsns 4.0 allows index.php?inform/add.html qid SQL injection.
1Whatsns
1Whatsns
Jun 17, 2026
Apr 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 22, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For exam...Show more
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.Show less
1Rocboss
1Rocboss
Jun 17, 2026
Apr 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
app/controllers/frontend/PostController.php in ROCBOSS V2.2.1 has SQL injection via the Post:doReward score paramter, as demonstrated by the /do/reward/3 URI.
1Tribulant
1Slideshow Gallery
Nov 21, 2024
Apr 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
1Ibm
2Bigfix Webui Profile Management
Bigfix Webui Software Distribution
Jun 17, 2026
Apr 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or del...Show more
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 155886.Show less
1Vpcsbd
1Integrated University Management System
Jun 17, 2026
Apr 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP...Show more
An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings).Show less
1Silverstripe
1Silverstripe
Jun 17, 2026
Apr 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
1Magento
1Magento
Jun 17, 2026
Apr 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior t...Show more
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.Show less
1Ibm
2Infosphere Information Server On Cloud
Infosphere Metadata Asset Manager
Nov 21, 2024
Apr 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in...Show more
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494.Show less