← Back
CWE-89

20,742 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,742)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1School Attendance Monitoring System Project
1School Attendance Monitoring System
Nov 21, 2024
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.
1Phpshe
1Phpshe
Jun 17, 2026
Mar 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 11, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (param...Show more
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id).Show less
1Layerbb
1Layerbb
Nov 21, 2024
Mar 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.
1Zrlog
1Zrlog
Nov 21, 2024
Mar 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.
1Zzcms
1Zzcms
Nov 21, 2024
Mar 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.
1Zzcms
1Zzcms
Nov 21, 2024
Mar 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.
1Zzcms
1Zzcms
Nov 21, 2024
Mar 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.
1Zzcms
1Zzcms
Nov 21, 2024
Mar 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.
1Dolibarr
1Dolibarr
Nov 21, 2024
Mar 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
1Phpshe
1Phpshe
Jun 17, 2026
Mar 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
1Ofcms Project
1Ofcms
Jun 17, 2026
Mar 6, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java.
1Bluecms Project
1Bluecms
Jun 17, 2026
Mar 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
1Ibm
1Financial Transaction Manager
Jun 17, 2026
Mar 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add,...Show more
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-ForceID: 155998.Show less
1Incsub
1Forminator
Jun 17, 2026
Mar 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
1Flarumchina
1Flarumchina
Jun 17, 2026
Mar 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.
1J2store
1J2store
Jun 17, 2026
Feb 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.
1Fizzday
1Gorose
Jun 17, 2026
Feb 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.
1Kohanaframework
1Kohana
Jun 17, 2026
Feb 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.
5Debian
OpensuseOracle+2 more
9Backports Sle
Communications Operations MonitorDebian Linux+6 more
Jun 17, 2026
Feb 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.