CWE-89
19,889 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (19,889)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. |
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. |
Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. |
In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...Show more |
Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. |
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. |
Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. |
The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from th...Show more |
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions. |
Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. |
Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6...Show more |
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. |
Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. |
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler read...Show more |
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is...Show more |
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. |
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions. |
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. |
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions. |