← Back
CWE-89

20,665 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,665)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wordpress
1Wordpress
May 6, 2026
Oct 1, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.
1Huge It
1Image Gallery
May 6, 2026
Sep 22, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the remove...Show more
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.Show less
1Apple
1Os X Server
May 6, 2026
Sep 19, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Ibm
1Qradar Security Information And Event Manager
May 6, 2026
Sep 18, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Spiceworks
1Spiceworks
May 6, 2026
Sep 17, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to different vulnerabi...Show more
SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6658 is for the XSS.Show less
1Orangehrm
1Orangehrm
May 6, 2026
Sep 17, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugin...Show more
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from third party information.Show less
1Ecava
1Integraxor
May 6, 2026
Sep 15, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Mpexsolutions
1Mx Smartimer
May 6, 2026
Sep 12, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Login.aspx in MPEX Business Solutions MX-SmartTimer before 13.19.18 allows remote attackers to execute arbitrary SQL commands via the ct100%24CPHContent%24password parameter.
1Mpay24 Project
1Mpay24
May 6, 2026
Sep 12, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.
1Wt Directory Project
1Wt Directory
May 6, 2026
Sep 11, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the wt_directory extension before 1.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Address Visualization With Google Maps Project
1Address Visualization With Google Maps
May 6, 2026
Sep 11, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Address visualization with Google Maps (st_address_map) extension before 0.3.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Flat Manager Project
1Flat Manager
May 6, 2026
Sep 11, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Flat Manager (flatmgr) extension before 2.7.10 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Group Office
1Groupoffice
May 6, 2026
Sep 11, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.
1Xrms Crm Project
1Xrms Crm
May 6, 2026
Sep 2, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.
1Invensys
1Wonderware Information Server
May 6, 2026
Aug 28, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Ibm
1Emptoris Contract Management
May 6, 2026
Aug 26, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated us...Show more
SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Php Sqrl Project
1Php Sqrl
May 6, 2026
Aug 25, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sqrl_verify.php in php-sqrl allows remote attackers to execute arbitrary SQL commands via the message parameter.
1Cacti
1Cacti
May 6, 2026
Aug 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Freereprintables
1Articlefr
May 6, 2026
Aug 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php.
1Bssys
1Rbs Bs Client
May 6, 2026
Aug 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allow remote attackers to execute arbitrary SQL commands via the (1) CARDS or (2) XACTION parameter.