CWE-89
20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,740)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Balderdash 1Waterline Sequel Nov 21, 2024 May 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potent...Show more |
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection. |
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection. |
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI. |
Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request. |
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. |
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter. |
1Trendmicro 1Smart Protection Server Nov 21, 2024 May 25, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the han...Show more |
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. |
1Easyservice Billing Project 1Easyservice Billing Nov 21, 2024 May 25, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0. |
An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly. |
1Bd 3Database Manager PerformaReadaNov 21, 2024 May 24, 2018 N/A· v4 6.3 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands...Show more |
1Bd 3Database Manager PerformaReadaNov 21, 2024 May 24, 2018 N/A· v4 5.6 MEDIUM· v3 3.8 LOW· v2 A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and Ino...Show more |
In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information. |
1Trendmicro 1Email Encryption Gateway Nov 21, 2024 May 23, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRequestDoma...Show more |
1Trendmicro 1Email Encryption Gateway Nov 21, 2024 May 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to disclose sensitive information on vulnerable installations due to a flaw in the formChange...Show more |
1Trendmicro 1Email Encryption Gateway Nov 21, 2024 May 23, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formConfiguration class. Authentication is re...Show more |
1Trendmicro 1Email Encryption Gateway Nov 21, 2024 May 23, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRegistration2 class. Authentication is re...Show more |
2Dolibarr Oracle2Data Integrator DolibarrJun 17, 2026 May 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_lis...Show more |
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes. |