CWE-89
20,711 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,711)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dasinfomedia 1Wpams Apartment Management System May 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter. |
1Dasinfomedia 1Hospital Management System May 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter. |
1Dasinfomedia 1Wpchurch Church Management System May 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter. |
1Dasinfomedia 1Wpgym Gym Management System May 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter. |
1Dasinfomedia 1School Management System May 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mojoomla School Management System for WordPress allows SQL Injection via the id parameter. |
1Dasinfomedia 1Smsmaster Multipurpose Sms Gateway May 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter. |
1Eventespresso 1Event Espresso Lite May 13, 2026 Sep 27, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php. |
1Support Ticket System Project 1Support Ticket System May 13, 2026 Sep 26, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) id parameter. |
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php. |
1Cashbackcomparisonscript 1Cash Back Comparison May 13, 2026 Sep 26, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/. |
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password. |
1Schneider Electric 1U.motion Builder May 13, 2026 Sep 26, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL comman...Show more |
1Wpdevart 1Responsive Image Gallery Gallery Album May 13, 2026 Sep 25, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gal...Show more |
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system. |
Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks. |
1Trendmicro 1Mobile Security May 13, 2026 Sep 22, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations. |
SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote attacker to inject arbitrary SQL commands via an XML-RPC encoded document sent as...Show more |
1Tecnovision 1Dlx Spot Player4 May 13, 2026 Sep 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password. |
1Helpdesk Pro Project 1Helpdesk Pro May 13, 2026 Sep 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticat...Show more |
1Pragyan Cms Project 1Pragyan Cms May 13, 2026 Sep 19, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure. |