← Back
CWE-89

20,648 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,648)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tecnick
1Tcexam
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to...Show more
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to admin/code/tce_edit_test.php or (2) subject_id parameter to admin/code/tce_show_all_questions.php.Show less
1Gajim
1Gajim
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the get_last_conversation_lines function in common/logger.py in Gajim before 0.15 allows remote attackers to execute arbitrary SQL commands via the jig parameter.
1Sinapsitech
4Esolar Duo Photovoltaic System Monitor
Esolar Light Photovoltaic System MonitorEsolar Photovoltaic System Monitor+1 more
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information fr...Show more
These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.Show less
1Agilefleet
2Fleetcommander
Fleetcommander Kiosk
Apr 29, 2026
Nov 18, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Pico
1Picopublisher
Apr 29, 2026
Nov 17, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php.
1B2evolution
1B2evolution
Apr 29, 2026
Nov 17, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter.
1Mybb
1Mybb
Apr 29, 2026
Nov 17, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to ad...Show more
SQL injection vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to execute arbitrary SQL commands via the conditions[usergroup][] parameter in a search action to admin/index.php.Show less
1Samedia
1Landshop
Apr 29, 2026
Nov 17, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter...Show more
Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter in a single action to admin/action/areas.php, or (3) start parameter in a show action to admin/action/pdf.php.Show less
1Havalite
1Cms
Apr 29, 2026
Nov 17, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in hava_post.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the postId parameter.
1Verifone
1Vericentre Web Console
Apr 29, 2026
Nov 15, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or...Show more
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36 allow remote attackers to execute arbitrary SQL commands via the (1) TerminalId, (2) ModelName, or (3) ApplicationName parameter.Show less
1Esri
1Arcgis Server
Apr 29, 2026
Nov 14, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.
1Mnogosearch
1Mnogosearch
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in mnoGoSearch before 3.3.12 allows remote attackers to execute arbitrary SQL commands via the hostname in a hypertext link.
1Scripte24shop
1Social Network Community
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL commands via the userId parameter.
1Seotoaster
1Seotoaster
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands v...Show more
Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member.Show less
1Apprain
1Apprain
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
1Trioniclabs
1Sentinel
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Scripte24shop
1Php Flirt Projekt
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the rub parameter.
1Neubivljiv
1Dota Openstats
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
2Troyef
Wordpress
2Scorm Cloud
Wordpress
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are...Show more
SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are obtained from third party information.Show less
12daybiz
1Video Community Portal Script
Apr 29, 2026
Oct 25, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in Video Community Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.