CWE-89
20,742 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,742)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1School Attendance Monitoring System Project 1School Attendance Monitoring System Nov 21, 2024 Mar 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view. |
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication. |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Mar 11, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (param...Show more |
LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter. |
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter. |
A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter. |
zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter. |
zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter. |
zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header. |
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit. |
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php. |
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. |
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. |
1Ibm 1Financial Transaction Manager Jun 17, 2026 Mar 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add,...Show more |
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission. |
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request. |
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter. |
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled. |
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled. |
5Debian OpensuseOracle+2 more9Backports Sle Communications Operations MonitorDebian Linux+6 moreJun 17, 2026 Feb 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. |