← Back
CWE-89

20,742 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,742)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
1Pbootcms
1Pbootcms
Jun 17, 2026
Feb 17, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php.
1Bagesoft
1Bagecms
Jun 17, 2026
Feb 17, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.
1Hotels Server Project
1Hotels Server
Jun 17, 2026
Feb 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled.
1Themerig
1Find A Place Cms Directory
Jun 17, 2026
Feb 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.
1Easy2map
1Easy2map Photos
Nov 21, 2024
Feb 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables
1Hgiga
1Oaklouds Mailsherlock
Nov 21, 2024
Feb 11, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi requ...Show more
SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.Show less
1Traq
1Traq
Nov 21, 2024
Feb 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Traq 3.7.1 allows SQL Injection via a tickets?search= URI.
1Xerox
29Workcentre 3655 Firmware
Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 more
Nov 21, 2024
Feb 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injec...Show more
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.Show less
1Abbyy
1Flexicapture
Nov 21, 2024
Feb 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order par...Show more
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter.Show less
1Bo Blog
1Bw
Jun 17, 2026
Feb 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this parameter is mishandled in the mode/admin.mode.php delBlockedBatch function.
1Bijiadao
1Waimai Super Cms
Jun 17, 2026
Feb 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Injection via the param array parameter to the /index.php?m=public&a=checkemail URI.
1Baijiacms Project
1Baijiacms
Jun 17, 2026
Feb 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request.
5Debian
OpensuseOracle+2 more
9Backports Sle
Communications Operations MonitorDebian Linux+6 more
Jun 17, 2026
Feb 6, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
1Advantech
1Webaccess/scada
Jun 17, 2026
Feb 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands.
2Coturn Project
Debian
2Coturn
Debian Linux
Nov 21, 2024
Feb 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in au...Show more
An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.Show less
1Connectwise
1Manageditsync
Aug 13, 2026
Feb 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively explo...Show more
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.Show less