← Back
CWE-89

20,739 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,739)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Mar 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result i...Show more
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.Show less
1Enalean
1Tuleap
Jun 17, 2026
Mar 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands.
1Westernbridgegroup
1Razor
Jun 17, 2026
Mar 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.p...Show more
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.Show less
1Bacula
1Bacula Web
Nov 21, 2024
Mar 7, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
1Afian
1Filerun
Jun 17, 2026
Mar 6, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&page=list_filetypes request.
1Afian
1Filerun
Jun 17, 2026
Mar 6, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=list request.
1Yxtcmf
1Yxtcmf
Jun 17, 2026
Mar 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in YxtCMF 3.1. SQL Injection exists in ShitiController.class.php via the ids array parameter to exam/shiti/delshiti.html.
1Clip Bucket
1Clipbucket
Jun 17, 2026
Mar 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php email parameter, and the ajax/commonAjax.p...Show more
An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php email parameter, and the ajax/commonAjax.php username parameter.Show less
1Yzmcms
1Yzmcms
Jun 17, 2026
Mar 1, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.
1School Management Script Project
1School Management Script
Jun 17, 2026
Feb 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php.
1Asanhamayesh
1Asanhamayesh Cms
Jun 17, 2026
Feb 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.
1Facetag Project
1Facetag
Nov 21, 2024
Feb 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
1Piwigo
1Piwigo
Jun 17, 2026
Feb 24, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator.
1Schools Alert Management Script Project
1Schools Alert Management Script
Jun 17, 2026
Feb 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter.
1Os Property Real Estate Project
1Os Property Real Estate
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.
2Belitsoft
Oracle
2Checklist
Data Integrator
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.
1Harmistechnology
1Ek Rishta
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter.
1Mlwebtechnologies
1Prayercenter
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.
1Alexandriabooklibrary
1Alexandria Book Library
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.
1Ibm
2Maximo Asset Management
Maximo Asset Management Essentials
Nov 21, 2024
Feb 22, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back...Show more
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.Show less