← Back
CWE-89

20,643 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,643)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Parallels
1Parallels Plesk Panel
Apr 29, 2026
Mar 12, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x before 9.5 MU#11, 10.0.x before MU#13, 10.1.x before MU#22, 10.2.x before MU#16, and 10.3.x before MU#...Show more
SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x before 9.5 MU#11, 10.0.x before MU#13, 10.1.x before MU#22, 10.2.x before MU#16, and 10.3.x before MU#5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in March 2012.Show less
1Ibm
1Tivoli Provisioning Manager Express For Software Distribution
Apr 29, 2026
Mar 6, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterA...Show more
Multiple SQL injection vulnerabilities in IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 allow remote attackers to execute arbitrary SQL commands via (1) a SOAP message to the Printer.getPrinterAgentKey function in the SoapServlet servlet, (2) the User.updateUserValue function in the register.do servlet, (3) the User.isExistingUser function in the logon.do servlet, (4) the Asset.getHWKey function in the CallHomeExec servlet, (5) the Asset.getMimeType function in the getAttachment (aka GetAttachmentServlet) servlet, (6) the addAsset.do servlet, or (7) a crafted EG2 file.Show less
1Cisco
7Business Edition 3000
Business Edition 3000 SoftwareBusiness Edition 5000+4 more
Apr 29, 2026
Mar 1, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with softwa...Show more
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a crafted SCCP registration, aka Bug ID CSCtu73538.Show less
1Powie
1Pfile
Apr 29, 2026
Feb 24, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in pfile/file.php in Powie pFile 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Lepton Cms
1Lepton
Apr 29, 2026
Feb 24, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter.
1Contimex
1Impulsio Cms
Apr 29, 2026
Feb 23, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in CONTIMEX Impulsio CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
1Advantech
1Advantech Webaccess
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for C...Show more
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.Show less
1Advantech
1Advantech Webaccess
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
1Advantech
1Advantech Webaccess
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.
1Advantech
1Advantech Webaccess
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string input.
1Dolibarr
1Dolibarr Erp/crm
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) row...Show more
Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to adherents/fiche.php.Show less
1Freelancerkit
1Freelancerkit
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in freelancerKit 2.35 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to the (1) notes and (2) tickets components.
1Zenphoto
1Zenphoto
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.
1Earl Miles
1Views
Apr 29, 2026
Feb 17, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific confi...Show more
SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."Show less
1Phpnuke
2Php Nuke
Web Links Module
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.
1Manfred Egger
1Bc Post2facebook
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Robert Gonda
1Rtg Files
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Mm Whtppr
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the White Papers (mm_whtppr) extension 0.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Typo3
1Toi Category
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
1Mathieu Vidal
1Mv Cooking
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild as of February 2...Show more
SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild as of February 2012.Show less