← Back
CWE-89

20,708 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,708)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bigtreecms
1Bigtree Cms
May 13, 2026
Jul 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via the tags array parameter.
1Glpi Project
1Glpi
May 13, 2026
Jul 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
1Hashtopus Project
1Hashtopus
May 13, 2026
Jul 27, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Hashtopus 1.5g allows remote authenticated users to execute arbitrary SQL commands via the format parameter in admin.php.
1Fiyo
1Fiyo Cms
May 13, 2026
Jul 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
1Web Dorado
1Contact Form Maker
May 13, 2026
Jul 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Tilde Cms Project
1Tilde Cms
May 13, 2026
Jul 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST reques...Show more
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php with the id parameter.Show less
1Finecms
1Finecms
May 13, 2026
Jul 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dayrui FineCms 5.0.9 has SQL Injection via the field parameter in an action=module, action=member, action=form, or action=related request to libraries/Template.php.
1Finecms
1Finecms
May 13, 2026
Jul 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dayrui FineCms 5.0.9 has SQL Injection via the catid parameter in an action=related request to libraries/Template.php.
1Finecms
1Finecms
May 13, 2026
Jul 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Template.php.
1Inmarsat
1Amosconnect 8
May 13, 2026
Jul 22, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Blind SQL injection in Inmarsat AmosConnect 8 login form allows remote attackers to access user credentials, including user names and passwords.
1Glpi Project
1Glpi
May 13, 2026
Jul 20, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
1Glpi Project
1Glpi
May 13, 2026
Jul 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.
1Idera
1Uptime Infrastructure Monitor
May 13, 2026
Jul 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
1Idera
1Uptime Infrastructure Monitor
May 13, 2026
Jul 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.
1Intelliants
1Subrion Cms
May 13, 2026
Jul 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
1Intelliants
1Subrion Cms
May 13, 2026
Jul 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
1Fiyo
1Fiyo Cms
May 13, 2026
Jul 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].
1Fiyo
1Fiyo Cms
May 13, 2026
Jul 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].
1Fiyo
1Fiyo Cms
May 13, 2026
Jul 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id'].
1Fiyo
1Fiyo Cms
May 13, 2026
Jul 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.