← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rxtec
1Rxadmin
Nov 21, 2024
Sep 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) g...Show more
Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or the (5) rxtec cookie to index.htm.Show less
1Seacms
1Seacms
Nov 21, 2024
Sep 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
1Zohocorp
1Manageengine Opmanager
Nov 21, 2024
Sep 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Anal...Show more
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.Show less
1Cwjoomla
2Cw Article Attachments Free
Cw Article Attachments Pro
Nov 21, 2024
Sep 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
1Ibm
2Business Automation Workflow
Business Process Manager
Nov 21, 2024
Sep 20, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modi...Show more
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 145109.Show less
1Arkextensions
1Jck Editor
Nov 21, 2024
Sep 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
1Zohocorp
1Manageengine Opmanager
Nov 21, 2024
Sep 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
1Slack Archivebot Project
1Slack Archivebot
Nov 21, 2024
Sep 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute()...Show more
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().Show less
1Zzcms
1Zzcms
Nov 21, 2024
Sep 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.
1Metinfo
1Metinfo
Nov 21, 2024
Sep 17, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.
1Tecdiary
1Simple Pos
Nov 21, 2024
Sep 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.
1I4a
1Donlinkage
Nov 21, 2024
Sep 16, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be exploited via specially crafted input, allowing an attacker to obtain information from a database. The vu...Show more
An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be exploited via specially crafted input, allowing an attacker to obtain information from a database. The vulnerability can only be triggered by an authorized user.Show less
1Ucms Project
1Ucms
Nov 21, 2024
Sep 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.
1E107
1E107
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The employee and sort_order parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
2Erpnext
Frappe
2Erpnext
Erpnext
May 8, 2026
Sep 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used...Show more
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The searchfield parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.Show less
1Processmaker
1Processmaker
Nov 21, 2024
Sep 10, 2018
N/A· v4
7.4 HIGH· v3
6.5 MEDIUM· v2
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters con...Show more
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain setups access the underlying operating system.Show less
1Thedaylightstudio
1Fuel Cms
Nov 21, 2024
Sep 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.