CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 126 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0771 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections | ||
| CVE-2022-27466 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do. | ||
| CVE-2022-28524 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2022 | ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | ||
| CVE-2022-27985 | Cri | 0.64 | 9.8 | 0.07 | Apr 26, 2022 | CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php. | ||
| CVE-2022-27984 | Cri | 0.64 | 9.8 | 0.07 | Apr 26, 2022 | CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php. | ||
| CVE-2022-27299 | Cri | 0.64 | 9.8 | 0.02 | Apr 26, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php. | ||
| CVE-2022-0782 | Cri | 0.64 | 9.8 | 0.02 | Apr 25, 2022 | The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an… | ||
| CVE-2022-0769 | Cri | 0.64 | 9.8 | 0.08 | Apr 25, 2022 | The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users),… | ||
| CVE-2022-0693 | Cri | 0.64 | 9.8 | 0.07 | Apr 25, 2022 | The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL… | ||
| CVE-2022-0657 | Cri | 0.64 | 9.8 | 0.02 | Apr 25, 2022 | The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an… | ||
| CVE-2022-27342 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2022 | Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult(). | ||
| CVE-2022-27341 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2022 | JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. | ||
| CVE-2022-28439 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid=4. | ||
| CVE-2022-28438 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=User&userid=. | ||
| CVE-2022-28437 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=Admin&userid=3. | ||
| CVE-2022-28436 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Hide&userid=. | ||
| CVE-2022-28435 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&action=displaygoal&value=1&roleid=1. | ||
| CVE-2022-28434 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&sid=2. | ||
| CVE-2022-28433 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=. | ||
| CVE-2022-28432 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=display&value=0&sid=2. |
- risk 0.64cvss 9.8epss 0.02
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections
- risk 0.64cvss 9.8epss 0.02
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
- risk 0.64cvss 9.8epss 0.01
ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.
- risk 0.64cvss 9.8epss 0.07
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
- risk 0.64cvss 9.8epss 0.07
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
- risk 0.64cvss 9.8epss 0.02
The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an…
- risk 0.64cvss 9.8epss 0.08
The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users),…
- risk 0.64cvss 9.8epss 0.07
The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL…
- risk 0.64cvss 9.8epss 0.02
The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an…
- risk 0.64cvss 9.8epss 0.01
Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().
- risk 0.64cvss 9.8epss 0.01
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid=4.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=User&userid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=Admin&userid=3.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Hide&userid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&action=displaygoal&value=1&roleid=1.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&sid=2.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=.
- risk 0.64cvss 9.8epss 0.01
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=display&value=0&sid=2.