← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mushroom Content Management System Project
1Mushroom Content Management System
Nov 21, 2024
Sep 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, resulting in a SQL inje...Show more
An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, resulting in a SQL injection vulnerability in getChannel() in the ChannelService.java file.Show less
1Swa
1Swa.jacad
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SWA SWA.JACAD 3.1.37 Build 024 has SQL Injection via the /academico/aluno/esqueci-minha-senha/ studentId parameter.
1Multiplanet
1Alphaindex Dictionaries
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
1Osthemeclub
1Timetable Schedule
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
1Super Cms Blog Pro Project
1Super Cms Blog Pro
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
1Thephpfactory
1Social Factory
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
1Thephpfactory
1Swap Factory
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
1Thephpfactory
1Collection Factory
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
1Thephpfactory
1Jobs Factory
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
1Thephpfactory
1Article Factory Manager
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
1Thephpfactory
1Raffle Factory
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
1Thephpfactory
1Penny Auction Factory
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
1Extensiondeveloper
1Questions
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
1Thephpfactory
1Reverse Auction Factory
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
1Joomlathat
1Music Collection
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
1Rausoft
1Id.prove
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell f...Show more
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.Show less
1Isweb
1Isweb
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the application and obtain sensitive information.
1Hpe
1Device Entitlement Gateway
Jun 17, 2026
Sep 27, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privileg...Show more
A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege.Show less
1Thinkphp
1Thinkphp
Nov 21, 2024
Sep 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
1Horus Cms Project
1Horus Cms
Nov 21, 2024
Sep 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Horus CMS allows SQL Injection, as demonstrated by a request to the /busca or /home URI.