CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 163 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-9315 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The newstatpress plugin before 1.0.1 for WordPress has SQL injection. | ||
| CVE-2015-9313 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element. | ||
| CVE-2015-9301 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2019 | The liveforms plugin before 3.2.0 for WordPress has SQL injection. | ||
| CVE-2019-14968 | Cri | 0.64 | 9.8 | 0.02 | Aug 12, 2019 | An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action. | ||
| CVE-2019-14801 | Cri | 0.64 | 9.8 | 0.02 | Aug 9, 2019 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. | ||
| CVE-2019-14754 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2019 | Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter. | ||
| CVE-2019-5476 | Cri | 0.64 | 9.8 | 0.02 | Aug 7, 2019 | An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands. | ||
| CVE-2019-14702 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An attacker can, for example, create an admin account. | ||
| CVE-2019-14695 | Cri | 0.64 | 9.8 | 0.03 | Aug 6, 2019 | A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers… | ||
| CVE-2016-10817 | Cri | 0.64 | 9.8 | 0.02 | Aug 1, 2019 | cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123). | ||
| CVE-2019-13572 | Cri | 0.64 | 9.8 | 0.02 | Aug 1, 2019 | The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection. | ||
| CVE-2018-20887 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2019 | cPanel before 74.0.0 allows SQL injection during database backups (SEC-420). | ||
| CVE-2019-5454 | Cri | 0.64 | 9.8 | 0.02 | Jul 30, 2019 | SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account. | ||
| CVE-2019-13026 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2019 | OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary. | ||
| CVE-2019-14313 | Cri | 0.64 | 9.8 | 0.04 | Jul 30, 2019 | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php. | ||
| CVE-2019-13571 | Cri | 0.64 | 9.8 | 0.04 | Jul 29, 2019 | A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | ||
| CVE-2019-9885 | Cri | 0.64 | 9.8 | 0.03 | Jul 25, 2019 | eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter. | ||
| CVE-2019-1010191 | Cri | 0.64 | 9.8 | 0.01 | Jul 24, 2019 | marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a… | ||
| CVE-2019-1010153 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php. | ||
| CVE-2019-1010148 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution. |
- risk 0.64cvss 9.8epss 0.02
The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
- risk 0.64cvss 9.8epss 0.02
The liveforms plugin before 3.2.0 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
- risk 0.64cvss 9.8epss 0.02
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
- risk 0.64cvss 9.8epss 0.02
Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An attacker can, for example, create an admin account.
- risk 0.64cvss 9.8epss 0.03
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers…
- risk 0.64cvss 9.8epss 0.02
cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
- risk 0.64cvss 9.8epss 0.02
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
- risk 0.64cvss 9.8epss 0.02
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.
- risk 0.64cvss 9.8epss 0.01
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.
- risk 0.64cvss 9.8epss 0.04
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
- risk 0.64cvss 9.8epss 0.04
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
- risk 0.64cvss 9.8epss 0.03
eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.
- risk 0.64cvss 9.8epss 0.01
marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a…
- risk 0.64cvss 9.8epss 0.02
zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.
- risk 0.64cvss 9.8epss 0.02
zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.