← Back
CWE-89

20,711 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,711)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dasinfomedia
1Wpams Apartment Management System
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
1Dasinfomedia
1Hospital Management System
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
1Dasinfomedia
1Wpchurch Church Management System
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
1Dasinfomedia
1Wpgym Gym Management System
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
1Dasinfomedia
1School Management System
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
1Dasinfomedia
1Smsmaster Multipurpose Sms Gateway
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
1Eventespresso
1Event Espresso Lite
May 13, 2026
Sep 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.
1Support Ticket System Project
1Support Ticket System
May 13, 2026
Sep 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) id parameter.
1Testlink
1Testlink
May 13, 2026
Sep 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.
1Cashbackcomparisonscript
1Cash Back Comparison
May 13, 2026
Sep 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.
1Faleemi
1Fsc 880 Firmware
May 13, 2026
Sep 26, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.
1Schneider Electric
1U.motion Builder
May 13, 2026
Sep 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL comman...Show more
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.Show less
1Wpdevart
1Responsive Image Gallery Gallery Album
May 13, 2026
Sep 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gal...Show more
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.Show less
1Xceedium
1Xsuite
May 13, 2026
Sep 25, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
1Wordpress
1Wordpress
May 13, 2026
Sep 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.
1Trendmicro
1Mobile Security
May 13, 2026
Sep 22, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
1Tapatalk
1Tapatalk
May 13, 2026
Sep 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote attacker to inject arbitrary SQL commands via an XML-RPC encoded document sent as...Show more
SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote attacker to inject arbitrary SQL commands via an XML-RPC encoded document sent as part of the user registration process.Show less
1Tecnovision
1Dlx Spot Player4
May 13, 2026
Sep 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.
1Helpdesk Pro Project
1Helpdesk Pro
May 13, 2026
Sep 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticat...Show more
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.Show less
1Pragyan Cms Project
1Pragyan Cms
May 13, 2026
Sep 19, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.