CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 159 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17072 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2019 | The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php. | ||
| CVE-2019-10757 | Cri | 0.64 | 9.8 | 0.01 | Oct 8, 2019 | knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB. | ||
| CVE-2015-9452 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2019 | The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter. | ||
| CVE-2015-9451 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2019 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter. | ||
| CVE-2015-9450 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2019 | The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter. | ||
| CVE-2019-17197 | Cri | 0.64 | 9.8 | 0.01 | Oct 5, 2019 | OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc. | ||
| CVE-2019-13957 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2019 | In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter. | ||
| CVE-2019-16999 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2019 | CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI. | ||
| CVE-2019-16696 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used. | ||
| CVE-2019-16695 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used. | ||
| CVE-2019-16694 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used. | ||
| CVE-2019-16644 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2019 | App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring. | ||
| CVE-2019-16642 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2019 | App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring. | ||
| CVE-2016-11000 | Cri | 0.64 | 9.8 | 0.02 | Sep 20, 2019 | The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter. | ||
| CVE-2019-15301 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2019 | A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter. | ||
| CVE-2019-14254 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2019 | An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL injections in userAccFunctions.php functions. Using this, an attacker can access passwords and/or grant access to the user account "user" in order… | ||
| CVE-2019-16264 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2019 | In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the database. | ||
| CVE-2019-16309 | Cri | 0.64 | 9.8 | 0.05 | Sep 14, 2019 | FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. | ||
| CVE-2019-16125 | Cri | 0.64 | 9.8 | 0.02 | Sep 9, 2019 | In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection. | ||
| CVE-2019-15872 | Cri | 0.64 | 9.8 | 0.02 | Sep 3, 2019 | The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. |
- risk 0.64cvss 9.8epss 0.02
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
- risk 0.64cvss 9.8epss 0.01
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
- risk 0.64cvss 9.8epss 0.02
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
- risk 0.64cvss 9.8epss 0.02
The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.
- risk 0.64cvss 9.8epss 0.02
The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter.
- risk 0.64cvss 9.8epss 0.01
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
- risk 0.64cvss 9.8epss 0.01
In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.
- risk 0.64cvss 9.8epss 0.01
CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.02
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
- risk 0.64cvss 9.8epss 0.01
App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring.
- risk 0.64cvss 9.8epss 0.02
App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.
- risk 0.64cvss 9.8epss 0.02
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL injections in userAccFunctions.php functions. Using this, an attacker can access passwords and/or grant access to the user account "user" in order…
- risk 0.64cvss 9.8epss 0.02
In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the database.
- risk 0.64cvss 9.8epss 0.05
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
- risk 0.64cvss 9.8epss 0.02
In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.
- risk 0.64cvss 9.8epss 0.02
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.