CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 161 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15566 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java. | ||
| CVE-2019-15565 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php. | ||
| CVE-2019-15564 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py. | ||
| CVE-2019-15562 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm | ||
| CVE-2019-15561 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js. | ||
| CVE-2019-15556 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php. | ||
| CVE-2019-15534 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update. | ||
| CVE-2019-15537 | Cri | 0.64 | 9.8 | 0.02 | Aug 23, 2019 | The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php. | ||
| CVE-2019-15536 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2019 | The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records. | ||
| CVE-2019-15535 | Cri | 0.64 | 9.8 | 0.02 | Aug 23, 2019 | Tasking Manager before 3.4.0 allows SQL Injection via custom SQL. | ||
| CVE-2015-9334 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The email-newsletter plugin through 20.15 for WordPress has SQL injection. | ||
| CVE-2014-10387 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection. | ||
| CVE-2017-18573 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection. | ||
| CVE-2017-18571 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316. | ||
| CVE-2017-18570 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. | ||
| CVE-2016-10921 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection. | ||
| CVE-2016-10917 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316. | ||
| CVE-2016-10916 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319. | ||
| CVE-2015-9335 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling. | ||
| CVE-2015-9333 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The cforms2 plugin before 14.6.10 for WordPress has SQL injection. |
- risk 0.64cvss 9.8epss 0.02
The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.
- risk 0.64cvss 9.8epss 0.01
The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
- risk 0.64cvss 9.8epss 0.01
The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.
- risk 0.64cvss 9.8epss 0.02
GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm
- risk 0.64cvss 9.8epss 0.01
FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
- risk 0.64cvss 9.8epss 0.01
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
- risk 0.64cvss 9.8epss 0.01
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
- risk 0.64cvss 9.8epss 0.02
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
- risk 0.64cvss 9.8epss 0.01
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
- risk 0.64cvss 9.8epss 0.02
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
- risk 0.64cvss 9.8epss 0.02
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.
- risk 0.64cvss 9.8epss 0.02
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
- risk 0.64cvss 9.8epss 0.02
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.
- risk 0.64cvss 9.8epss 0.02
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
- risk 0.64cvss 9.8epss 0.02
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
- risk 0.64cvss 9.8epss 0.02
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.