CWE-89
20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands. |
1Opentext 1Document Sciences Xpression Nov 21, 2024 Jan 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection. |
1Openhacker Project 1Openhacker Nov 21, 2024 Jan 2, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure and remote code execution |
1Oturia 1Smart Google Code Inserter Nov 21, 2024 Jan 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() funct...Show more |
1Muslim Matrimonial Script Project 1Muslim Matrimonial Script May 13, 2026 Dec 30, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter. |
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the...Show more |
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the...Show more |
SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the docu...Show more |
SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the...Show more |
2Debian Zend2Debian Linux Zend FrameworkMay 13, 2026 Dec 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter. |
1Php Multivendor Ecommerce Project 1Php Multivendor Ecommerce May 13, 2026 Dec 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter. |
Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter. |
1Single Theater Booking Script Project 1Single Theater Booking Script May 13, 2026 Dec 28, 2017 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter. |
1Phpmybackuppro 1Phpmybackuppro May 13, 2026 Dec 28, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters. |
1Resume Clone Script Project 1Resume Clone Script May 13, 2026 Dec 27, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter. |
1Ordermanagementscript 1Professional Service Script May 13, 2026 Dec 27, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter. |
1Car Rental Script Project 1Car Rental Script May 13, 2026 Dec 27, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter. |
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter. |