CWE-89
20,687 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,687)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 1Automation License Manager May 6, 2026 Oct 13, 2016 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to execute arbitrary SQL commands via crafted traffic to TCP port 4410. |
Zotpress plugin for WordPress SQLi in zp_get_account() |
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla |
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6 |
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla |
XSS and SQLi in huge IT gallery v1.1.5 for Joomla |
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection |
1Dukapress Project 1Dukapress May 6, 2026 Oct 6, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Blind SQL Injection in wordpress plugin dukapress v2.5.9 |
1Filedownload Project 1Filedownload May 6, 2026 Oct 6, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Blind SQL Injection in filedownload v1.4 wordpress plugin |
1Pivotal Software 1Spring Data Jpa May 6, 2026 Oct 5, 2016 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attacke...Show more |
1Cisco 1Secure Firewall Management Center May 6, 2026 Oct 5, 2016 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485. |
2Adodb Project Fedoraproject2Adodb FedoraMay 6, 2026 Oct 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting. |
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted...Show more |
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids paramete...Show more |
SQL injection vulnerability in chat/staff/default.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary SQL commands via the user name field. |
SQL injection vulnerability in news pages in Cargotec Navis WebAccess before 2016-08-10 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields. |
1Redhat 3Dashbuilder Jboss Bpm SuiteJboss Enterprise Brms PlatformMay 6, 2026 Aug 5, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL...Show more |
SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
1Rockwellautomation 1Factorytalk Energrymetrix May 6, 2026 Jul 28, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |