← Back
CWE-89

20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zechat Project
1Zechat
Jun 17, 2026
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
1Getaffiligator
1Affiligator
Jun 17, 2026
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request.
1Quickad Project
1Quickad
Jun 17, 2026
Jan 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.
1Fairsketch
1Rise Ultimate Project Manager
Nov 21, 2024
Jan 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/.
1Tribalsystems
1Zenario
Jun 17, 2026
Jan 22, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module.
1Moxa
1Softcms Lab View
Nov 21, 2024
Jan 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified. Attackers can explo...Show more
A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified. Attackers can exploit this vulnerability to access SoftCMS without knowing the user's password.Show less
1Icyphoenix
1Icyphoenix
Jun 17, 2026
Jan 14, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Icy Phoenix 2.2.0.105 allows SQL injection via an unapprove request to admin_kb_art.php or the order parameter to admin_jr_admin.php, related to functions_kb.php.
1Ijoomla
1Ad Agency
Jun 17, 2026
Jan 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` parameters to index.php.
1Wpjobboard
1Wpjobboard
Jun 17, 2026
Jan 14, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-alerts module, with a request to wp-admin/admin.php.
1Skyboxsecurity
1Skybox Platform
Nov 21, 2024
Jan 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/VersionWebService via a soapenv:Body element.
1Wp Events Calendar Project
1Wp Events Calendar
Nov 21, 2024
Jan 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
1Muvikoscript
1Muviko
Nov 21, 2024
Jan 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; t...Show more
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; the (3) movie_id parameter to themes/flixer/ajax/get_rating.php; the (4) rating or (5) movie_id parameter to themes/flixer/ajax/update_rating.php; or the (6) id parameter to themes/flixer/ajax/set_player_source.php.Show less
1Slidervilla
1Dbox Slider
Nov 21, 2024
Jan 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).
1Slidervilla
1Smooth Slider
Nov 21, 2024
Jan 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Smooth Slider plugin through 2.8.6 for WordPress has SQL Injection via smooth-slider.php (trid parameter).
1Slidervilla
1Testimonial Slider
Nov 21, 2024
Jan 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Jan 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information...Show more
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 133637.Show less
1Phpsugar
1Php Melody
Nov 21, 2024
Jan 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
1Gespage
1Gespage
Nov 21, 2024
Jan 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or show_month parameter to (2) webapp/users...Show more
Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or show_month parameter to (2) webapp/users/blhistory.jsp or (3) webapp/users/prhistory.jsp.Show less
1Microsemi
1S350i Firmware
Nov 21, 2024
Jan 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execute arbitrary SQL commands via vectors involving a username.
1Newsbee Project
1Newsbee
Nov 21, 2024
Jan 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands.