← Back
CWE-89

20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,927)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Innovadeluxe
1Manufacturer Or Supplier Alphabetical Search
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sen...Show more
SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink, IdxrmanufacturerFunctions::getManufacturersLike and IdxrmanufacturerFunctions::getSuppliersLike.Show less
1Remyandrade
1Daily Habit Tracker
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.
1Supabase
1Postgres
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase...Show more
Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Specifically, /pg_meta/default/query is for SQL queries that are entered in an intended UI by an authorized user. Nothing is injected.Show less
1Store Opart
1Op'art Easy Redirect
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().
1Wpbookingcalendar
1Booking Calendar
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user...Show more
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.Show less
1Xxyopen
1Novel Plus
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.
1Xxyopen
1Novel Plus
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list
1Xxyopen
1Novel Plus
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list
1Jishenghua
1Jsherp
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters w...Show more
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload to bypass jshERP's protection mechanism in `safeSqlParse` method for sql injection.Show less
1Xxyopen
1Novel Plus
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.
1Xxyopen
1Novel Plus
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list
1Zope
1Sqlalchemyda
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance...Show more
SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no workaround for the problem.Show less
1Atmail
1Atmail
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
1Podlove
1Podlove Subscribe Button
Jun 17, 2026
Feb 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up to, and including, 1.3.10 due to insuff...Show more
The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up to, and including, 1.3.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.Show less
1Hipresta
1Gift Wrapping Pro
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiA...Show more
SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.Show less
1Bookingcalendar Project
1Bookingcalendar
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.p...Show more
SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.Show less
1Xxyopen
1Novel Plus
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list
1Jishenghua
1Jsherp
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well eno...Show more
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload to bypass jshERP's protection mechanism in `safeSqlParse` method for sql injection.Show less
1Jishenghua
1Jsherp
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well eno...Show more
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload to bypass jshERP's protection mechanism in `safeSqlParse` method for sql injection.Show less
1Jishenghua
1Jsherp
Jun 17, 2026
Feb 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious...Show more
jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious payload to bypass jshERP's protection mechanism.Show less