← Back
CWE-89

20,687 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,687)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cacti
1Cacti
May 6, 2026
Apr 11, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
1Huawei
1Policy Center Firmware
May 6, 2026
Apr 11, 2016
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to system databases.
1Cacti
1Cacti
May 6, 2026
Apr 11, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
1Apache
1Jetspeed
May 6, 2026
Apr 11, 2016
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/u...Show more
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.Show less
1Symantec
1Endpoint Protection Manager
May 6, 2026
Mar 18, 2016
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
SQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Ibm
13Change And Configuration Management Database
Maximo Asset ManagementMaximo Asset Management Essentials+10 more
May 6, 2026
Mar 12, 2016
N/A· v4
5.4 MEDIUM· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 befo...Show more
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Cuore
1Ec Cube Help Plugin
May 6, 2026
Feb 19, 2016
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the Help plug-in 1.3.5 and earlier in Cuore EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Sap
1Netweaver Application Server Java
Apr 21, 2026
Feb 16, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
1Samsung
1X14j Firmware
May 6, 2026
Feb 7, 2016
N/A· v4
6.5 MEDIUM· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Cisco Unified Communications Manager 10.5(2.13900.9) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCux99227.
2Cisco
Sun
2Opensolaris
Rv Series Router Firmware
May 6, 2026
Jan 27, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574.
1Advantech
1Webaccess
May 6, 2026
Jan 15, 2016
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Joomla
1Joomla
May 6, 2026
Jan 12, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
SQL injection vulnerability in Joomla! 3.x before 3.4.7 allows attackers to execute arbitrary SQL commands via unspecified vectors.
1Progress
1Whatsup Gold
May 6, 2026
Jan 8, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP requ...Show more
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.Show less
1Cisco
1Unified Communications Manager
May 6, 2026
Jan 8, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCut66767.
1Ibm
1Curam Social Program Management
May 6, 2026
Jan 3, 2016
N/A· v4
5.4 MEDIUM· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Ibm
1Openpages Grc Platform
May 6, 2026
Jan 1, 2016
N/A· v4
5.4 MEDIUM· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Bokublock
2Bbadminviewscontrol
Bbadminviewscontrol213
May 6, 2026
Dec 30, 2015
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via...Show more
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Welcart
1Welcart E Commerce
May 6, 2026
Dec 29, 2015
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) search[column] or (2) switch para...Show more
Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) search[column] or (2) switch parameter.Show less
1Epiphanyhealthdata
1Cardio Server
May 6, 2026
Dec 27, 2015
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in the login page in Epiphany Cardio Server 3.3 allows remote attackers to execute arbitrary SQL commands via a crafted URL.
1Progress
1Whatsup Gold
May 6, 2026
Dec 27, 2015
N/A· v4
6.5 MEDIUM· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports com...Show more
Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter.Show less