← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kliqqi
1Kliqqi Cms
Nov 21, 2024
Apr 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI.
1Ericssonlg
1Ipecs Nms
Jun 17, 2026
Apr 22, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.
1Adaltech
1G Ticket
Nov 21, 2024
Apr 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.
1Cliquemania
1Loja Virtual
Nov 21, 2024
Apr 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.
1Apache
1Fineract
Nov 21, 2024
Apr 20, 2018
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn't have authorization for by way of the 'r...Show more
Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn't have authorization for by way of the 'reportName' parameter.Show less
1Apache
1Fineract
Nov 21, 2024
Apr 20, 2018
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' which are appended directly with SQL statem...Show more
Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' which are appended directly with SQL statements. A hacker/user can inject/draft the 'orderBy' query parameter by way of the "order" param in such a way to read/update the data for which he doesn't have authorization.Show less
1Apache
1Fineract
Nov 21, 2024
Apr 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be done in Methods like re...Show more
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be done in Methods like retrieveAuditEntries of AuditsApiResource Class and retrieveCommands of MakercheckersApiResource Class.Show less
1Apache
1Fineract
Nov 21, 2024
Apr 20, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' whi...Show more
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with SQL statements. A hacker/user can inject/draft the 'orderBy' and 'sortOrder' query parameter in such a way to read/update the data for which he doesn't have authorization.Show less
1Thinkphp
1Thinkphp
Nov 21, 2024
Apr 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
1Nagios
1Nagios Xi
Jun 17, 2026
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.
1Nagios
1Nagios Xi
Jun 17, 2026
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection v...Show more
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.Show less
1Cybozu
1Garoon
Nov 21, 2024
Apr 16, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
1Iscripts
1Eswap
Nov 21, 2024
Apr 11, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
1Ca
1Workload Automation Ae
Jun 17, 2026
Apr 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Apr 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Apr 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut paramet...Show more
Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut parameter).Show less
1Icmsdev
1Icms
Jun 17, 2026
Apr 10, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request.
2Redhat
Theforeman
2Foreman
Satellite
Nov 21, 2024
Apr 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
1Apache
1Hive
Nov 21, 2024
Apr 5, 2018
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
1Zzcms
1Zzcms
Jun 17, 2026
Apr 5, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.