← Back
CWE-89

20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Foodpanda Clone Project
1Foodpanda Clone
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
1Expedia Clone Project
1Expedia Clone
May 13, 2026
Dec 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
1Scubez
1Posty Readymade Classifieds
May 13, 2026
Dec 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
1Ibm
1Financial Transaction Manager
May 13, 2026
Dec 11, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to vie...Show more
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 132926.Show less
1Scubez
1Posty Readymade Classifieds
May 13, 2026
Dec 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.
1Techno Portfolio Management Panel Project
1Techno Portfolio Management Panel
May 13, 2026
Dec 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
1Ibm
1Atlas Ediscovery Process Management
May 13, 2026
Dec 7, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in th...Show more
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126683.Show less
1Fiyo
1Fiyo Cms
May 13, 2026
Dec 4, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.
1Fiyo
1Fiyo Cms
May 13, 2026
Dec 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
1Piwigo
1Piwigo
May 13, 2026
Dec 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by...Show more
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. tags.php is affected: values of the edit_list parameters are not sanitized; these are used to construct an SQL query and retrieve a list of registered users into the application.Show less
1Ark Web
1A Reserve
May 13, 2026
Dec 1, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
1Ark Web
1A Member
May 13, 2026
Dec 1, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
1Cisco
1Prime Service Catalog
May 13, 2026
Nov 30, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due...Show more
A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied input that is used in SQL queries. An attacker could exploit this vulnerability by sending a crafted SQL statement to an affected system. Successful exploitation could allow the attacker to read entries in some database tables. Cisco Bug IDs: CSCvg30333.Show less
1Bigtreecms
1Bigtree Cms
May 13, 2026
Nov 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data fro...Show more
A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The attack uses an admin/trees/add/process request with a crafted _tags[] parameter that is mishandled in a later admin/ajax/dashboard/approve-change request.Show less
1Inlinks Project
1Inlinks
May 13, 2026
Nov 27, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.p...Show more
SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.php.Show less
1Huawei
1Fusionsphere
May 13, 2026
Nov 22, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
FusionSphere V100R006C00SPC102(NFV) has an SQL injection vulnerability. An authenticated, remote attacker could craft interface messages carrying malicious SQL statements and send them to a target device. Successful expl...Show more
FusionSphere V100R006C00SPC102(NFV) has an SQL injection vulnerability. An authenticated, remote attacker could craft interface messages carrying malicious SQL statements and send them to a target device. Successful exploit could allow the attacker to launch an SQL injection attack and execute SQL commands.Show less
1Fiyo
1Fiyo Cms
May 13, 2026
Nov 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login...Show more
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.Show less
1Tt Rss
1Tiny Tiny Rss
May 13, 2026
Nov 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
1S9y
1Serendipity
May 13, 2026
Nov 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure
1Zohocorp
1Manageengine Applications Manager
May 13, 2026
Nov 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.