CWE-89
19,889 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (19,889)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions. |
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. |
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. |
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. |
Subscriber SQL Injection in GamiPress <= 7.8.7 versions. |
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. |
Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. |
Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. |
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. |
Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions. |
Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions. |
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions. |
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions. |
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions. |
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions. |
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions. |
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions. |
Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions. |
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. |
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. |