← Back
CWE-89

20,742 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,742)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1S Cms
1S Cms
Jun 17, 2026
Apr 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
1Mkcms Project
1Mkcms
Jun 17, 2026
Apr 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
1Codecabin
1Wp Go Maps
Jun 17, 2026
Apr 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
1Tongda2000
1Office Anywhere
Jun 17, 2026
Apr 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/approve_center/list/input_form/work_handle.php run_id parameter.
1Pivotal Software
1Concourse
Jun 17, 2026
Apr 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the atta...Show more
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.Show less
1Domoticz
1Domoticz
Jun 17, 2026
Mar 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
1Grandstream
1Ucm6204 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
1Harmistechnology
1Je Messenger
Jun 17, 2026
Mar 29, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be execut...Show more
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database.Show less
1Bluecms Project
1Bluecms
Jun 17, 2026
Mar 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of m...Show more
A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes.Show less
1Nagios
1Incident Manager
Jun 17, 2026
Mar 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.
1Nagios
1Nagios Xi
Jun 17, 2026
Mar 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.
1Laravel
1Framework
Jun 17, 2026
Mar 28, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.
1Librenms
1Librenms
Nov 21, 2024
Mar 28, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during a search.
1Teclib Edition
1Gestionnaire Libre De Parc Informatique
Jun 17, 2026
Mar 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 26, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.
1Risi
1Gestao De Horarios
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection.
1Sqlitemanager
1Sqlitemanager
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.
1Portier
1Portier
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ri...Show more
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.Show less
1Booking Calendar Project
1Booking Calendar
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
1Ens
1Webgalamb
Nov 21, 2024
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.