CWE-89
20,742 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,742)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter. |
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value. |
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter. |
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter. |
A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php. |
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter. |
1Hotels Server Project 1Hotels Server Jun 17, 2026 Feb 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled. |
1Themerig 1Find A Place Cms Directory Jun 17, 2026 Feb 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter. |
Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables |
1Hgiga 1Oaklouds Mailsherlock Nov 21, 2024 Feb 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi requ...Show more |
Traq 3.7.1 allows SQL Injection via a tickets?search= URI. |
1Xerox 29Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 moreNov 21, 2024 Feb 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injec...Show more |
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order par...Show more |
Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this parameter is mishandled in the mode/admin.mode.php delBlockedBatch function. |
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Injection via the param array parameter to the /index.php?m=public&a=checkemail URI. |
An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request. |
5Debian OpensuseOracle+2 more9Backports Sle Communications Operations MonitorDebian Linux+6 moreJun 17, 2026 Feb 6, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. |
WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands. |
2Coturn Project Debian2Coturn Debian LinuxNov 21, 2024 Feb 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in au...Show more |
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively explo...Show more |