CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 160 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-6719 | Cri | 0.64 | 9.8 | 0.02 | Aug 28, 2019 | The sharebar plugin before 1.2.2 for WordPress has SQL injection. | ||
| CVE-2015-9352 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The wp-polls plugin before 2.72 for WordPress has SQL injection. | ||
| CVE-2019-15659 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. | ||
| CVE-2019-15646 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The rsvpmaker plugin before 6.2 for WordPress has SQL injection. | ||
| CVE-2018-21004 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection. | ||
| CVE-2018-21003 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The buddyforms plugin before 2.2.8 for WordPress has SQL injection. | ||
| CVE-2015-9344 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The link-log plugin before 2.1 for WordPress has SQL injection. | ||
| CVE-2019-15533 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php. | ||
| CVE-2019-15558 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java. | ||
| CVE-2019-15557 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key. | ||
| CVE-2019-15555 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php. | ||
| CVE-2019-15560 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. | ||
| CVE-2019-15559 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | DianoxDragon Hawn before 2019-07-10 allows SQL injection. | ||
| CVE-2019-15574 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php. | ||
| CVE-2019-15573 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php. | ||
| CVE-2019-15572 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php. | ||
| CVE-2019-15571 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php. | ||
| CVE-2019-15569 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java. | ||
| CVE-2019-15568 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels. | ||
| CVE-2019-15567 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature. |
- risk 0.64cvss 9.8epss 0.02
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The wp-polls plugin before 2.72 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
- risk 0.64cvss 9.8epss 0.02
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The link-log plugin before 2.1 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.01
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
- risk 0.64cvss 9.8epss 0.01
XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.
- risk 0.64cvss 9.8epss 0.02
XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.
- risk 0.64cvss 9.8epss 0.01
FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php.
- risk 0.64cvss 9.8epss 0.01
The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
- risk 0.64cvss 9.8epss 0.01
DianoxDragon Hawn before 2019-07-10 allows SQL injection.
- risk 0.64cvss 9.8epss 0.01
Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.
- risk 0.64cvss 9.8epss 0.01
Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.
- risk 0.64cvss 9.8epss 0.01
Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.
- risk 0.64cvss 9.8epss 0.01
The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.
- risk 0.64cvss 9.8epss 0.01
HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.
- risk 0.64cvss 9.8epss 0.01
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
- risk 0.64cvss 9.8epss 0.01
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.