← Back
CWE-89

20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Applications Manager
May 13, 2026
Nov 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
1Zohocorp
1Manageengine Applications Manager
May 13, 2026
Nov 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
1Zohocorp
1Manageengine Applications Manager
May 13, 2026
Nov 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
1Zohocorp
1Manageengine Applications Manager
May 13, 2026
Nov 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
1Zohocorp
1Manageengine Applications Manager
May 13, 2026
Nov 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
1Cisco
1Unified Communications Domain Manager
May 13, 2026
Nov 16, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Inj...Show more
A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The vulnerability is due to a lack of input validation on user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected system. An exploit could allow the attacker to determine the presence of certain values in the database. Cisco Bug IDs: CSCvf36682.Show less
1Metalgenix
1Genixcms
May 13, 2026
Nov 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to r...Show more
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.Show less
1Ingenious School Management System Project
1Ingenious School Management System
May 13, 2026
Nov 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
/view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request.
1Zohocorp
1Manageengine Applications Manager
May 13, 2026
Nov 5, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
1Zohocorp
1Manageengine Applications Manager
May 13, 2026
Nov 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
1Tenable
2Security Center
Securitycenter
Aug 17, 2026
Nov 2, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vul...Show more
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.Show less
1Wordpress
1Wordpress
May 13, 2026
Nov 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approa...Show more
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.Show less
1Cisco
1Prime Collaboration Provisioning
May 13, 2026
Nov 2, 2017
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity...Show more
A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. The attacker could read or write information from the SQL database. The vulnerability is due to a lack of proper validation on user-supplied input within SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application. An exploit could allow the attacker to determine the presence of certain values and write malicious input in the SQL database. The attacker would need to have valid user credentials. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.3. Cisco Bug IDs: CSCvf47935.Show less
1Hp
2Arcsight Enterprise Security Manager
Arcsight Enterprise Security Manager Express
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.
1Zomato Clone Script Project
1Zomato Clone Script
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
1Website Broker Script Project
1Website Broker Script
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
1Vastal
1Agent Zone
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom par...Show more
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951, CVE-2009-3497, and CVE-2012-0982.Show less
1Online Exam Test Application Project
1Online Exam Test Application
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
1Nicephpscripts
1Nice Php Faq Script
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.
1Fake Magazine Cover Script Project
1Fake Magazine Cover Script
May 13, 2026
Oct 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.