← Back
CWE-89

20,645 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dominique Clause
1Search Autocomplete
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the Search Autocomplete module before 7.x-2.1 for Drupal allows remote authenticated users with the "use search_autocomplete" permission to execute arbitrary SQL commands via unspecified ve...Show more
SQL injection vulnerability in the Search Autocomplete module before 7.x-2.1 for Drupal allows remote authenticated users with the "use search_autocomplete" permission to execute arbitrary SQL commands via unspecified vectors.Show less
1Blueteck
1Witze Addon
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in jokes/index.php in the Witze addon 0.9 for deV!L'z Clanportal allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.
1Rivetcode
1Rivettracker
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.
1Limesurvey
1Limesurvey
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these det...Show more
SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.Show less
1Peter Kovacs
1Timesheet Next Gen
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
1Wesjones
1Multisite Search
Apr 29, 2026
Sep 18, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the Multisite Search module 6.x-2.2 for Drupal allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the Site table prefix field.
1Siemens
2Simatic Pcs7
Wincc
Apr 29, 2026
Sep 18, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.
1Silverstripe
1Silverstripe
Apr 29, 2026
Sep 17, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Silverstripe
1Silverstripe
Apr 29, 2026
Sep 17, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute a...Show more
SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.Show less
1Silverstripe
1Silverstripe
Apr 29, 2026
Sep 17, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execu...Show more
SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via the locale parameter.Show less
1Limesurvey
1Limesurvey
Apr 29, 2026
Sep 15, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
1Imgpals
1Img Pals Photo Host
Apr 29, 2026
Sep 15, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. NOTE: the provenance of thi...Show more
Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Bananadance
1Banana Dance
Apr 29, 2026
Sep 15, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in search.php in Banana Dance, possibly B.1.5 and earlier, allows remote attackers to execute arbitrary SQL commands via the category parameter.
1Dell
1Sonicwall Viewpoint
Apr 29, 2026
Sep 15, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter.
1Bananadance
1Banana Dance
Apr 29, 2026
Sep 15, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in user.php in Banana Dance before B.1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Ibm
6Change And Configuration Management Database
Maximo Asset ManagementMaximo Service Desk+3 more
Apr 29, 2026
Sep 10, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configur...Show more
SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Ibm
6Change And Configuration Management Database
Maximo Asset ManagementMaximo Service Desk+3 more
Apr 29, 2026
Sep 10, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configur...Show more
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Ibm
6Change And Configuration Management Database
Maximo Asset ManagementMaximo Service Desk+3 more
Apr 29, 2026
Sep 10, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Manage...Show more
SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.Show less
1Open Emr
1Openemr
Apr 29, 2026
Sep 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter.
1Chatelao
1Php Address Book
Apr 29, 2026
Sep 9, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE:...Show more
Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565.Show less