← Back
CWE-89

20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
1Webaccess
Nov 21, 2024
Jan 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.
1Opentext
1Document Sciences Xpression
Nov 21, 2024
Jan 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.
1Openhacker Project
1Openhacker
Nov 21, 2024
Jan 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure and remote code execution
1Oturia
1Smart Google Code Inserter
Nov 21, 2024
Jan 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() funct...Show more
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] variable before passing it as input into the SQL query.Show less
1Muslim Matrimonial Script Project
1Muslim Matrimonial Script
May 13, 2026
Dec 30, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter.
1Rubyonrails
1Ruby On Rails
May 13, 2026
Dec 29, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the...Show more
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted inputShow less
1Rubyonrails
1Ruby On Rails
May 13, 2026
Dec 29, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the...Show more
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted inputShow less
1Rubyonrails
1Rails
May 13, 2026
Dec 29, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the docu...Show more
SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted inputShow less
1Rubyonrails
1Rails
May 13, 2026
Dec 29, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the...Show more
SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted inputShow less
2Debian
Zend
2Debian Linux
Zend Framework
May 13, 2026
Dec 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.
1Cells
1Blog
May 13, 2026
Dec 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.
1Single Theater Booking Script Project
1Single Theater Booking Script
May 13, 2026
Dec 28, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter.
1Phpmybackuppro
1Phpmybackuppro
May 13, 2026
Dec 28, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.
1Resume Clone Script Project
1Resume Clone Script
May 13, 2026
Dec 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.
1Ordermanagementscript
1Professional Service Script
May 13, 2026
Dec 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.
1Car Rental Script Project
1Car Rental Script
May 13, 2026
Dec 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.
1Dolibarr
1Dolibarr Erp/crm
May 13, 2026
Dec 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.