← Back
CWE-89

20,741 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,741)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Thimpress
1Learnpress
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
1Frontaccounting
1Frontaccounting
Jun 17, 2026
Jan 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction...Show more
includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction.php filterType parameter.Show less
1Earclink
1Espcms P8
Jun 17, 2026
Jan 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS data...Show more
EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database.Show less
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Jan 3, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter.
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Jan 3, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter.
1Plikli
1Plikli Cms
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to join_group.php or (2) comment_id parameter to story.php.
1Yeswiki
1Cercopitheque
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.
1Bijiadao
1Waimai Super Cms
Jun 17, 2026
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI.
1Inxedu Project
1Inxedu
Jun 17, 2026
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
inxedu through 2018-12-24 has a SQL Injection vulnerability that can lead to information disclosure via the deleteFaveorite/ PATH_INFO. The vulnerable code location is com.inxedu.os.edu.controller.user.UserController#del...Show more
inxedu through 2018-12-24 has a SQL Injection vulnerability that can lead to information disclosure via the deleteFaveorite/ PATH_INFO. The vulnerable code location is com.inxedu.os.edu.controller.user.UserController#deleteFavorite (aka deleteFavorite in com/inxedu/os/edu/controller/user/UserController.java), where courseFavoritesService.deleteCourseFavoritesById is mishandled during use of MyBatis. NOTE: UserController.java has a spelling variation in an annotation: a @RequestMapping("/deleteFaveorite/{ids}") line followed by a "public ModelAndView deleteFavorite" line.Show less
1Simply Blog Project
1Simply Blog
Jun 17, 2026
Jan 1, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.
1Wuzhicms
1Wuzhicms
Nov 21, 2024
Dec 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.
1Generic Content Management System Project
1Generic Content Management System
Nov 21, 2024
Dec 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
user/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authentication bypass.
1Generic Content Management System Project
1Generic Content Management System
Nov 21, 2024
Dec 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Administrator/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authentication bypass.
1Frontaccounting
1Frontaccounting
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.
1Battelle
1V2i Hub
Nov 21, 2024
Dec 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Battelle V2I Hub 3.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the tmx/TmxCtl/src/lib/PluginStatus.cpp and TmxControl::user_info() function, which could allow the at...Show more
Battelle V2I Hub 3.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the tmx/TmxCtl/src/lib/PluginStatus.cpp and TmxControl::user_info() function, which could allow the attacker to view, add, modify or delete information in the back-end database.Show less
1Battelle
1V2i Hub
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Battelle V2I Hub 2.5.1 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to /api/PluginStatusActions.php and /status/pluginStatus.php using the jtSorting or id pa...Show more
Battelle V2I Hub 2.5.1 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to /api/PluginStatusActions.php and /status/pluginStatus.php using the jtSorting or id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.Show less
1Crashfix Project
1Crashfix
Nov 21, 2024
Dec 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function.
1S Cms
1S Cms
Nov 21, 2024
Dec 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter.
1S Cms
1S Cms
Nov 21, 2024
Dec 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter.
1S Cms
1S Cms
Nov 21, 2024
Dec 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.