← Back
CWE-89

20,650 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,650)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Roundcube
1Webmail
Apr 29, 2026
Nov 5, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, cond...Show more
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.Show less
1Landing Pages Project
1Landing Pages Plugin
Apr 29, 2026
Oct 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.
1Quassel Irc
1Quassel Irc
Apr 29, 2026
Oct 23, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message.
1Hp
2Imc Service Operation Management Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZDI-CAN...Show more
SQL injection vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZDI-CAN-1664.Show less
1Status
1Statusnet
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
1Kwoksys
1Information Server
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbitrary SQL commands via the (1) hardwareType, (2) hardwareStatus, or (3)...Show more
SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbitrary SQL commands via the (1) hardwareType, (2) hardwareStatus, or (3) hardwareLocation parameter in a search command.Show less
1Cisco
1Identity Services Engine Software
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCug90502.
1Alienvault
1Open Source Security Information Management
Apr 29, 2026
Oct 9, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-i...Show more
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3) radar-iso27001-A11AccessControl-pot.php, (4) radar-iso27001-A10Com_OP_Mgnt-pot.php, or (5) radar-pci-potential.php in RadarReport/.Show less
1Vtiger
1Vtiger Crm
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php...Show more
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559.Show less
1Cisco
1Unified Communications Domain Manager
Apr 29, 2026
Oct 2, 2013
N/A· v4
N/A· v3
5.5 MEDIUM· v2
SQL injection vulnerability in the web framework in Cisco Unified Communications Domain Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh96567.
1Ibm
1Maximo Asset Management
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Ibm
1Maximo Asset Management
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Ibm
1Maximo Asset Management
Apr 29, 2026
Oct 1, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
1Simone Tellini
1Mod Accounting
Apr 29, 2026
Sep 30, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.
1Real Estate Php Script
1Real Estate Php Script
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in property_listings_detail.php in Real Estate PHP Script allows remote attackers to execute arbitrary SQL commands via the listingid parameter.
1Rodrigo Coimbra
1Nospam Pti
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter.
1Moodle
1Moodle
Apr 29, 2026
Sep 16, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against...Show more
Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.Show less
1Hp
2Identity Driven Manager
Procurve Manager
Apr 29, 2026
Sep 16, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via...Show more
Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter.Show less
1Sap
1Netweaver
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE."
1Indianic
1Testimonial Plugin
Apr 29, 2026
Sep 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to...Show more
SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php.Show less