← Back
CWE-89

20,687 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,687)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
1Automation License Manager
May 6, 2026
Oct 13, 2016
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to execute arbitrary SQL commands via crafted traffic to TCP port 4410.
1Zotpress Project
1Zotpress
May 6, 2026
Oct 6, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zotpress plugin for WordPress SQLi in zp_get_account()
1Huge It
1Huge It Catalog
May 6, 2026
Oct 6, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
1Huge It
1Portfolio Gallery
May 6, 2026
Oct 6, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
1Huge It
1Video Gallery
May 6, 2026
Oct 6, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
1Huge It
1Gallery
May 6, 2026
Oct 6, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
1Progress
1Whatsup Gold
May 6, 2026
Oct 6, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
1Dukapress Project
1Dukapress
May 6, 2026
Oct 6, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Blind SQL Injection in wordpress plugin dukapress v2.5.9
1Filedownload Project
1Filedownload
May 6, 2026
Oct 6, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Blind SQL Injection in filedownload v1.4 wordpress plugin
1Pivotal Software
1Spring Data Jpa
May 6, 2026
Oct 5, 2016
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attacke...Show more
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.Show less
1Cisco
1Secure Firewall Management Center
May 6, 2026
Oct 5, 2016
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.
2Adodb Project
Fedoraproject
2Adodb
Fedora
May 6, 2026
Oct 3, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
1Otrs
1Faq
May 6, 2026
Sep 17, 2016
N/A· v4
9.4 CRITICAL· v3
9.0 HIGH· v2
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted...Show more
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.Show less
1Vbulletin
1Vbulletin
May 6, 2026
Aug 30, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids paramete...Show more
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.Show less
1Readydesk
1Readydesk
May 6, 2026
Aug 26, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in chat/staff/default.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary SQL commands via the user name field.
1Navis
1Webaccess
May 6, 2026
Aug 22, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in news pages in Cargotec Navis WebAccess before 2016-08-10 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Moxa
1Softcms
May 6, 2026
Aug 8, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.
1Redhat
3Dashbuilder
Jboss Bpm SuiteJboss Enterprise Brms Platform
May 6, 2026
Aug 5, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL...Show more
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.Show less
1Ec Cube
1Discount Coupon
May 6, 2026
Aug 1, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Rockwellautomation
1Factorytalk Energrymetrix
May 6, 2026
Jul 28, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.