← Back
CWE-89

20,741 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,741)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dthdevelopment
1Dt Register
Nov 21, 2024
Feb 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitabl...Show more
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web server.Show less
1Css Tricks
1Chat2
Jun 17, 2026
Feb 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.
1Phpmyadmin
1Phpmyadmin
Jun 17, 2026
Jan 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.
1S Cms
1S Cms
Jun 17, 2026
Jan 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
1Phpshe
1Phpshe
Jun 17, 2026
Jan 23, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.
1Phpshe
1Phpshe
Jun 17, 2026
Jan 23, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.
1Phpwind
1Phpwind
Jun 17, 2026
Jan 23, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup database" option.
1Hotels Server Project
1Hotels Server
Jun 17, 2026
Jan 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.
1Nedi
1Nedi
Nov 21, 2024
Jan 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Jan 15, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Tiki before 17.2, the user task component is vulnerable to a SQL Injection via the tiki-user_tasks.php show_history parameter.
1Cubecart
1Cubecart
Nov 21, 2024
Jan 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
1Oxid Esales
1Eshop
Nov 21, 2024
Jan 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php.
1Shopware
1Shopware
Nov 21, 2024
Jan 15, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Shopware before 5.4.3 allows SQL Injection by remote authenticated users, aka SW-21404.
1Skymoonlabs
1Cleanto
Jun 17, 2026
Jan 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter.
1Skymoonlabs
1Cleanto
Jun 17, 2026
Jan 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter.
1Icmsdev
1Icms
Jun 17, 2026
Jan 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter.
1Xiaocms
1Xiaocms
Jun 17, 2026
Jan 11, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename.
1Cimtechniques
1Cimscan
Nov 21, 2024
Jan 10, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.
1Nelson It
1Open Source Erp
Jun 17, 2026
Jan 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
1Ricoh
8D2200 Firmware
D5500 FirmwareD5510 Firmware+5 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D...Show more
SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive Whiteboard Controller Type2 V3.0 to V3.1.10137.0 attached (D5520, D6510, D7500, D8400) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.Show less