CWE-89
20,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. |
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter. |
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter. |
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action. |
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter. |
1Cisco 1Unified Communications Domain Manager May 13, 2026 Nov 16, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Inj...Show more |
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to r...Show more |
1Ingenious School Management System Project 1Ingenious School Management System May 13, 2026 Nov 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 /view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request. |
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 5, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter. |
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 5, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request. |
1Tenable 2Security Center SecuritycenterAug 17, 2026 Nov 2, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vul...Show more |
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approa...Show more |
1Cisco 1Prime Collaboration Provisioning May 13, 2026 Nov 2, 2017 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity...Show more |
1Hp 2Arcsight Enterprise Security Manager Arcsight Enterprise Security Manager ExpressMay 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection. |
1Zomato Clone Script Project 1Zomato Clone Script May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. |
1Website Broker Script Project 1Website Broker Script May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php. |
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom par...Show more |
1Online Exam Test Application Project 1Online Exam Test Application May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action. |
1Nicephpscripts 1Nice Php Faq Script May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525. |
1Fake Magazine Cover Script Project 1Fake Magazine Cover Script May 13, 2026 Oct 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter. |