CWE-89
20,741 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,741)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dthdevelopment 1Dt Register Nov 21, 2024 Feb 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitabl...Show more |
An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability. |
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature. |
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter. |
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter. |
PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter. |
phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup database" option. |
1Hotels Server Project 1Hotels Server Jun 17, 2026 Jan 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter. |
A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component. |
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter. |
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. |
The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php. |
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404. |
Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter. |
Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter. |
An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter. |
An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename. |
In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code. |
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter. |
1Ricoh 8D2200 Firmware D5500 FirmwareD5510 Firmware+5 moreNov 21, 2024 Jan 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D...Show more |