← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
2Network Automation
Network Operations Management Ultimate
Jun 17, 2026
May 22, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely explo...Show more
SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow Remote SQL Injection.Show less
1Microfocus
1Service Manager
Jun 17, 2026
May 22, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
1Iscripts
1Eswap
Nov 21, 2024
May 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
1Iscripts
1Eswap
Nov 21, 2024
May 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
1Pbootcms
1Pbootcms
Nov 21, 2024
May 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.
1Open Emr
1Openemr
Jun 17, 2026
May 18, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.
1Projectpier
1Projectpier
Nov 21, 2024
May 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.
1Nagios
1Nagios Xi
Nov 21, 2024
May 16, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
1Nagios
1Nagios Xi
Nov 21, 2024
May 16, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
1Nagios
1Nagios Xi
Nov 21, 2024
May 16, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
1Nagios
1Nagios Xi
Nov 21, 2024
May 16, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
1Advantech
4Webaccess
Webaccess/nmsWebaccess Dashboard+1 more
Jun 17, 2026
May 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and pri...Show more
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been identified, which may allow an attacker to disclose sensitive information from the host.Show less
1Gouguoyin
1Phprap
Nov 21, 2024
May 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function.
1Pivotal Software
1Greenplum Command Center
Nov 21, 2024
May 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database...Show more
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database contents.Show less
1Synology
1Media Server
Jun 17, 2026
May 10, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.
2Prestashop
Responsive Mega Menu Pro Project
2Prestashop
Responsive Mega Menu Pro
Jun 17, 2026
May 10, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function...Show more
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function calls in the code parameter.Show less
1Csp Mysql User Manager Project
1Csp Mysql User Manager
Nov 21, 2024
May 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.
1Hrsale Project
1Hrsale
Nov 21, 2024
May 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.
1Ibm
1Qradar Security Information And Event Manager
Nov 21, 2024
Apr 26, 2018
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-en...Show more
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 134811.Show less
1Mitel
2Mivoice Connect
St 14.2
Jun 17, 2026
Apr 25, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated atta...Show more
A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the signin interface. A successful exploit could allow an attacker to extract sensitive information from the database.Show less