← Back
CWE-89

20,701 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,701)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Virtuemart
1Virtuemart
May 13, 2026
May 29, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index....Show more
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.Show less
1E107
1E107
May 13, 2026
May 29, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.
1Netapp
1Oncommand Unified Manager Core Package
May 13, 2026
May 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Wp Olivecart
2Olivecart
Olivecartpro
May 13, 2026
May 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors.
1Ipswitch
2Moveit Dmz
Moveit Transfer 2017
May 13, 2026
May 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.
1Joomla
1Joomla
May 13, 2026
May 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
1Infor
1Enterprise Asset Management
May 13, 2026
May 16, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.
1Dolibarr
1Dolibarr Erp/crm
May 13, 2026
May 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.
1Tibco
2Spotfire Analytics Platform For Aws
Spotfire Server
May 13, 2026
May 9, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerab...Show more
TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks.Show less
1Accellion
1File Transfer Appliance
May 13, 2026
May 5, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.
1Accellion
1File Transfer Appliance
May 13, 2026
May 5, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
1Xirrus
1Arrayos
May 13, 2026
May 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Genixcms
1Genixcms
May 13, 2026
May 1, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.
1Wbce
1Wbce Cms
May 13, 2026
Apr 28, 2017
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
1Opentext
1Documentum Content Server
May 13, 2026
Apr 25, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability...Show more
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by use of a backspace character in an injected string. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513.Show less
1Oracle
1Scripting
May 13, 2026
Apr 24, 2017
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Eas...Show more
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).Show less
1Yeager
1Yeager Cms
May 13, 2026
Apr 24, 2017
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.
1Yeager
1Yeager Cms
May 13, 2026
Apr 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.
1Exponentcms
1Exponent Cms
May 13, 2026
Apr 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.
1Cybozu
1Garoon
May 13, 2026
Apr 20, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Cybozu Garoon before 4.2.2.