CWE-89
19,889 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (19,889)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Subscriber SQL Injection in Tourfic <= 2.22.5 versions. |
Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions. |
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. |
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. |
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. |
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. |
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. |
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. |
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up to, and including, 4.5.4 due to insufficient escaping o...Show more |
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 of managers.php, the application assi...Show more |
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to a...Show more |
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfilt...Show more |
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltrat...Show more |
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. |
Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. |
Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection.
This issue affects YMC Filter: from n/a through 3.11.5. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a t...Show more |
Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. |
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 du...Show more |