← Back
CWE-89

20,711 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,711)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dtracker Project
1Dtracker
May 13, 2026
Sep 14, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
1Eyesofnetwork
1Eyesofnetwork
May 13, 2026
Sep 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.
1Eyesofnetwork
1Eyesofnetwork
May 13, 2026
Sep 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input validation in include/...Show more
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input validation in include/function.php.Show less
1Eyesofnetwork
1Eyesofnetwork
May 13, 2026
Sep 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT UPDATE" section.
1Osticket
1Osticket
May 13, 2026
Sep 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
1Emc
1Appsync
May 13, 2026
Sep 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EMC AppSync (all versions prior to 3.5) contains a SQL injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.
1Blog Project
1Blog
May 13, 2026
Sep 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php.
1Alegrocart
1Alegrocart
May 13, 2026
Sep 11, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in up...Show more
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote authenticated users with a valid Paypal transaction token to execute arbitrary SQL commands via the ref parameter in the (3) orderUpdate function in upload/catalog/extension/payment/paypal.php.Show less
1User Dashboard Project
1User Dashboard
May 13, 2026
Sep 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Eyesofnetwork
1Eyesofnetwork
May 13, 2026
Sep 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the group_id cookie to side.php.
1Eyesofnetwork
1Eyesofnetwork
May 13, 2026
Sep 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the user_id cookie to header.php, a related issue to CVE-2017-1000060.
1Dolibarr
1Dolibarr
May 13, 2026
Sep 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter.
1Dolibarr
1Dolibarr
May 13, 2026
Sep 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.
1Opwglobal
3Sitesentinel Integra 100 Firmware
Sitesentinel Integra 500 FirmwareSitesentinel Isite Atg Firmware
May 13, 2026
Sep 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189...Show more
A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. The application is vulnerable to injection of malicious SQL queries via the input from the client.Show less
1Synology
1Photo Station
May 13, 2026
Sep 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type paramete...Show more
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.Show less
1Cisco
1Emergency Responder
May 13, 2026
Sep 7, 2017
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-su...Show more
A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection filters. An attacker could exploit this vulnerability by sending crafted URLs that include SQL statements. An exploit could allow the attacker to view or modify entries in some database tables, affecting the integrity of the data. Cisco Bug IDs: CSCvb58973.Show less
1Sefrengo
1Sefrengo
May 13, 2026
Sep 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sefrengo before 1.6.5 beta2.
1Concretecms
1Concrete Cms
May 13, 2026
Sep 7, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Concrete5 5.7.3.1.
1Pragyan Cms Project
1Pragyan Cms
May 13, 2026
Sep 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Pragyan CMS 3.0.
1Tune Library Project
1Tune Library
May 13, 2026
Sep 7, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.