← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gxlcms
1Gxlcms Qy
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary P...Show more
The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary PHP code by placing it after a <?php substring, and then using INTO OUTFILE with a .php filename.Show less
1Openresty
1Openresty
Jun 17, 2026
Apr 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass...Show more
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenRestyShow less
1Square 9
1Globalforms
Jun 17, 2026
Mar 28, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter allows remote authenticated attackers to execute arbitrary SQL commands. It is possible to upgrade...Show more
An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter allows remote authenticated attackers to execute arbitrary SQL commands. It is possible to upgrade access to full server compromise via xp_cmdshell. In some cases, the authentication requirement for the attack can be met by sending the default admin credentials.Show less
2Debian
Firebirdsql
2Debian Linux
Firebird
Nov 21, 2024
Mar 28, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
1Google
1Android
Nov 21, 2024
Mar 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.
1Unisys
2Clearpath Eportal Manager
Eportal 2200
Jun 17, 2026
Mar 26, 2018
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the management interface in ePortal Manager allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
1Zzcms
1Zzcms
Jun 17, 2026
Mar 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
1Phpshe
1Phpshe
Jun 17, 2026
Mar 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a SQL injection in the PHPSHE 1.6 userbank parameter.
1Geutebrueck
2G Cam/efd 2250 Firmware
Topfd 2125 Firmware
Jun 17, 2026
Mar 22, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An SQL injection vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow an attacker to alter stored data.
1Gitlab
1Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.
1Yiiframework
1Yii
Jun 17, 2026
Mar 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocume...Show more
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.Show less
1Invisioncommunity
1Invision Power Board
Nov 21, 2024
Mar 20, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter.
1Unify
1Openscape Deployment Service
Nov 21, 2024
Mar 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Kentico
1Xperience
Jun 17, 2026
Mar 19, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
2Debian
Schedmd
2Debian Linux
Slurm
Jun 17, 2026
Mar 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
1Trendmicro
1Email Encryption Gateway
Jun 17, 2026
Mar 15, 2018
N/A· v4
6.8 MEDIUM· v3
8.3 HIGH· v2
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target syste...Show more
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.Show less
1Trendmicro
1Email Encryption Gateway
Jun 17, 2026
Mar 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
1Trendmicro
1Email Encryption Gateway
Jun 17, 2026
Mar 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
1Joomla
1Joomla
Jun 17, 2026
Mar 15, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
1Unitrends
1Backup
Jun 17, 2026
Mar 14, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system an...Show more
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system and subsequently execute arbitrary commands.Show less