← Back
CWE-89

20,889 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,889)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpulike
1Wp Ulike
Jun 17, 2026
May 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to,...Show more
The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'status' and 'id' attributes of the 'wp_ulike_counter' and 'wp_ulike' shortcodes in all versions up to, and including, 4.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.Show less
1Wedevs
1Wp Erp
Jun 17, 2026
May 2, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1...Show more
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.13.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with accounting manager or admin access, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.Show less
1Weblizar
1School Management
Jun 17, 2026
May 2, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from n/a through 10.3.4.
-
-
Jun 17, 2026
May 1, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the id parameter.
1Logint
1Lomag Warehouse Management
Jun 17, 2026
May 1, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.
1Bladex
1Springblade
Jun 17, 2026
Apr 30, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.
1Wallosapp
1Wallos
Jun 17, 2026
Apr 30, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.
-
-
Jun 17, 2026
Apr 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components.
-
-
Jun 17, 2026
Apr 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in shipup before v.3.3.0 allows a remote attacker to escalate privileges via the getShopID function.
-
-
Jun 17, 2026
Apr 30, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the HfHeropaymentGatewayBackModuleFrontController::initContent() function.
1Limbas
1Limbas
Jun 17, 2026
Apr 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.
-
-
Jun 17, 2026
Apr 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method.
-
-
Jun 17, 2026
Apr 29, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL commands via the AutosuggestSearchModuleFrontController::initContent(), and AutosuggestSearchModuleF...Show more
SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL commands via the AutosuggestSearchModuleFrontController::initContent(), and AutosuggestSearchModuleFrontController::getKbProducts() components.Show less
-
-
Jun 17, 2026
Apr 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands via the FsModel::getFlashSales method.
-
-
Jun 17, 2026
Apr 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::addGiftToCart method.
-
-
Jun 17, 2026
Apr 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.
1Ecommerce Codeigniter Bootstrap Project
1Ecommerce Codeigniter Bootstrap
Jun 17, 2026
Apr 29, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Or...Show more
SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.Show less
1Ecommerce Codeigniter Bootstrap Project
1Ecommerce Codeigniter Bootstrap
Jun 17, 2026
Apr 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.
1Onethink
1Onethink
Jun 17, 2026
Apr 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.
1Znuny
1Znuny
Jun 17, 2026
Apr 29, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.