CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 162 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-10687 | Cri | 0.64 | 9.8 | 0.03 | Aug 21, 2019 | KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request. | ||
| CVE-2014-10379 | Cri | 0.64 | 9.8 | 0.02 | Aug 21, 2019 | The duplicate-post plugin before 2.6 for WordPress has SQL injection. | ||
| CVE-2016-10909 | Cri | 0.64 | 9.8 | 0.02 | Aug 21, 2019 | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. | ||
| CVE-2019-4483 | Cri | 0.64 | 9.8 | 0.02 | Aug 20, 2019 | IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the… | ||
| CVE-2019-4481 | Cri | 0.64 | 9.8 | 0.02 | Aug 20, 2019 | IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the… | ||
| CVE-2015-9330 | Cri | 0.64 | 9.8 | 0.02 | Aug 20, 2019 | The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection. | ||
| CVE-2015-9324 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection. | ||
| CVE-2014-10376 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. | ||
| CVE-2017-18548 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The note-press plugin before 0.1.2 for WordPress has SQL injection. | ||
| CVE-2016-10904 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The olimometer plugin before 2.57 for WordPress has SQL injection. | ||
| CVE-2015-9326 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection. | ||
| CVE-2015-9325 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The visitors-online plugin before 0.4 for WordPress has SQL injection. | ||
| CVE-2019-13578 | Cri | 0.64 | 9.8 | 0.03 | Aug 15, 2019 | A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php. | ||
| CVE-2016-10888 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues. | ||
| CVE-2016-10887 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues. | ||
| CVE-2015-9310 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. | ||
| CVE-2019-15025 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. | ||
| CVE-2017-18514 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection. | ||
| CVE-2016-10889 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. | ||
| CVE-2015-9316 | Cri | 0.64 | 9.8 | 0.03 | Aug 14, 2019 | The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter. |
- risk 0.64cvss 9.8epss 0.03
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
- risk 0.64cvss 9.8epss 0.02
The duplicate-post plugin before 2.6 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the…
- risk 0.64cvss 9.8epss 0.02
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the…
- risk 0.64cvss 9.8epss 0.02
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
- risk 0.64cvss 9.8epss 0.02
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The note-press plugin before 0.1.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The olimometer plugin before 2.57 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The visitors-online plugin before 0.4 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.03
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.
- risk 0.64cvss 9.8epss 0.02
The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
- risk 0.64cvss 9.8epss 0.02
The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
- risk 0.64cvss 9.8epss 0.02
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
- risk 0.64cvss 9.8epss 0.02
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
- risk 0.64cvss 9.8epss 0.02
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
- risk 0.64cvss 9.8epss 0.03
The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.