← Back
CWE-89

20,650 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,650)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openwebanalytics
1Open Web Analytics
Apr 29, 2026
Jan 15, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the owa_email_address parameter in a base.passwordResetRequest...Show more
SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the owa_email_address parameter in a base.passwordResetRequest action to index.php.Show less
1Redhat
2Cloudforms Management Engine
Manageiq Enterprise Virtualization Manager
Apr 29, 2026
Jan 11, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute...Show more
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.Show less
1Ibm
4Atlas Ediscovery Process Management
Atlas SuiteDisposal And Governance Management For It+1 more
Apr 29, 2026
Jan 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Mana...Show more
SQL injection vulnerability in IBM Atlas eDiscovery Process Management 6.0.1.5 and earlier and 6.0.2, Disposal and Governance Management for IT 6.0.1.5 and earlier and 6.0.2, and Global Retention Policy and Schedule Management 6.0.1.5 and earlier and 6.0.2 in IBM Atlas Suite (aka Atlas Policy Suite) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.Show less
1Cynthia Fridsma
1Horizon Quick Content Management System
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter.
1Naxtech
1Cms Afroditi
Apr 29, 2026
Jan 8, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to default.asp.
2Osgeo
Umn
2Mapserver
Mapserver
Apr 29, 2026
Jan 5, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted...Show more
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.Show less
1Fatfreecrm
1Fat Free Crm
Apr 29, 2026
Jan 2, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) t...Show more
Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.Show less
1Zenphoto
1Zenphoto
Apr 29, 2026
Dec 31, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.
1Cisco
1Unified Presence Server
Apr 29, 2026
Dec 31, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh35615.
1Esri
1Arcgis Server
Apr 29, 2026
Dec 30, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to the map or feature service.
2Openx
Revive Adserver
2Openx
Revive Adserver
Apr 29, 2026
Dec 28, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL...Show more
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.Show less
1Cybozu
1Garoon
Apr 29, 2026
Dec 28, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input.
1Etoshop
1Classifieds Creator
Apr 29, 2026
Dec 24, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to...Show more
Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.Show less
1Redhat
1Enterprise Mrg
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."
1Ibm
2Sterling B2b Integrator
Sterling File Gateway
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Etoshop
1C2c Forward Auction Creator
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to au...Show more
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp.Show less
1Etoshop
1Dynamic Biz Website Builder Quickweb
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (...Show more
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp.Show less
1Idleman
1Leed
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to execute arbitrary SQL commands via the id parameter in a removeFolder action.
1Iscripts
1Autohoster
Apr 29, 2026
Dec 20, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransferstatus.php, (2) checktransferstatusbck...Show more
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransferstatus.php, (2) checktransferstatusbck.php, or (3) additionalsettings.php; or (4) invno parameter to payinvoiceothers.php.Show less
1Ncrafts
1Formcraft
Apr 29, 2026
Dec 20, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.