← Back
CWE-89

20,715 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,715)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Letodms Project
1Letodms
May 13, 2026
Oct 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Softwarepublico
1E Sic
May 13, 2026
Oct 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
1Softwarepublico
1E Sic
May 13, 2026
Oct 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
1Softwarepublico
1E Sic
May 13, 2026
Oct 23, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
1Panasonic
1Kx Hjb1000 Firmware
May 13, 2026
Oct 20, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
1Gsi Office
1Winpat Portal
May 13, 2026
Oct 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
1Realtyna
1Realtyna Property Listing
May 13, 2026
Oct 18, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action,...Show more
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting, or (9) pwizard parameter to administrator/index.php.Show less
1Phpsugar
1Php Melody
May 13, 2026
Oct 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
1Phpsugar
1Php Melody
May 13, 2026
Oct 18, 2017
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
1Zorovavi/blog Project
1Zorovavi/blog
May 13, 2026
Oct 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
1Store Locator Project
1Store Locator
May 13, 2026
Oct 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.
1Softwarepublico
1E Sic
May 13, 2026
Oct 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area).
1Phpbugtracker Project
1Phpbugtracker
May 13, 2026
Oct 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.
1Phpbugtracker Project
1Phpbugtracker
May 13, 2026
Oct 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to project.php, the (2) group_id parameter to group.php,...Show more
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to project.php, the (2) group_id parameter to group.php, the (3) status_id parameter to status.php, the (4) resolution_id parameter to resolution.php, the (5) severity_id parameter to severity.php, the (6) priority_id parameter to priority.php, the (7) os_id parameter to os.php, or the (8) site_id parameter to site.php.Show less
1Qnap
1Qts Helpdesk
May 13, 2026
Oct 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require a...Show more
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.Show less
1Frappe
1Frappe
May 13, 2026
Oct 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.
1Phpcollab
1Phpcollab
May 13, 2026
Oct 3, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/dele...Show more
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to calendar/deletecalendar.php.Show less
1Dasinfomedia
1Wphrm Human Resource Management System
May 13, 2026
Oct 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
1Opentext
1Document Sciences Xpression
May 13, 2026
Oct 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: docum...Show more
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.Show less
1Opentext
1Document Sciences Xpression
May 13, 2026
Oct 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.actio...Show more
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.Show less