CWE-89
20,739 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,739)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wpsupportplus 1Wp Support Plus Responsive Ticket System Nov 21, 2024 Mar 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result i...Show more |
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands. |
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.p...Show more |
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server. |
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata§ion=cpanel&page=list_filetypes request. |
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users§ion=cpanel&page=list request. |
An issue was discovered in YxtCMF 3.1. SQL Injection exists in ShitiController.class.php via the ids array parameter to exam/shiti/delshiti.html. |
An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php email parameter, and the ajax/commonAjax.p...Show more |
\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html. |
1School Management Script Project 1School Management Script Jun 17, 2026 Feb 28, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php. |
1Asanhamayesh 1Asanhamayesh Cms Jun 17, 2026 Feb 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter. |
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action. |
Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator. |
1Schools Alert Management Script Project 1Schools Alert Management Script Jun 17, 2026 Feb 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter. |
1Os Property Real Estate Project 1Os Property Real Estate Jun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter. |
2Belitsoft Oracle2Checklist Data IntegratorJun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter. |
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter. |
1Mlwebtechnologies 1Prayercenter Jun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. |
1Alexandriabooklibrary 1Alexandria Book Library Jun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter. |
1Ibm 2Maximo Asset Management Maximo Asset Management EssentialsNov 21, 2024 Feb 22, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back...Show more |