← Back
CWE-89

20,883 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,883)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ruvar
1Ruvaroa
Jun 17, 2026
May 7, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.aspx.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.
1Sem Cms
1Semcms
Jun 17, 2026
May 7, 2024
N/A· v4
6.5 MEDIUM· v3
6.5 MEDIUM· v2
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be la...Show more
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263317 was assigned to this vulnerability.Show less
1Roothub
1Roothub
Jun 17, 2026
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..
1Roothub
1Roothub
Jun 17, 2026
May 7, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
1Hsclabs
1Mailinspector
Jun 17, 2026
May 7, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteLis...Show more
SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteList.php component.Show less
1Glpi Project
1Glpi
Jun 17, 2026
May 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. This vulnerability is fixed in 10.0.15.
1Glpi Project
1Glpi
Jun 17, 2026
May 7, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of...Show more
GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved searches feature to alter another user account data take control of it. This vulnerability is fixed in 10.0.15.Show less
-
-
Jun 17, 2026
May 6, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the data parameter to models/ir_model.py:IrModel::...Show more
A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the data parameter to models/ir_model.py:IrModel::chech_model.Show less
-
-
Jun 17, 2026
May 6, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker to gain privileges via a query to IZITools::query_check, IZIToo...Show more
A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker to gain privileges via a query to IZITools::query_check, IZITools::query_fetch, or IZITools::query_execute.Show less
-
-
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe:...Show more
A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.Show less