VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 213 of 1,043
  • CVE-2017-14844HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.

  • CVE-2017-14843HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14842HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14396CriSep 12, 2017
    risk 0.60cvss 9.8epss 0.03

    In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

  • CVE-2017-9429HigJun 13, 2017
    risk 0.60cvss 8.8epss 0.03

    SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.

  • CVE-2017-9418HigJun 12, 2017
    risk 0.60cvss 8.8epss 0.02

    SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php.

  • CVE-2017-7952HigMay 16, 2017
    risk 0.60cvss 8.8epss 0.01

    INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.

  • CVE-2015-7568CriApr 24, 2017
    risk 0.60cvss 9.8epss 0.04

    SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.

  • CVE-2015-7564CriApr 12, 2017
    risk 0.60cvss 9.8epss 0.03

    Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b)…

  • CVE-2015-4592HigJan 10, 2017
    risk 0.60cvss 8.8epss 0.03

    eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.

  • CVE-2026-84073CriSep 18, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-75746CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.01

    ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to…

  • CVE-2026-3627CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2026-51346CriAug 17, 2026
    risk 0.59cvss 9.1epss 0.01

    SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.

  • CVE-2026-48381CriAug 11, 2026
    risk 0.59cvss 9.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to…

  • CVE-2026-19053CriAug 10, 2026
    risk 0.59cvss 9.1epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.

  • CVE-2026-18473CriAug 9, 2026
    risk 0.59cvss 9.1epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

  • CVE-2026-34191CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

  • CVE-2026-12713CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by…

  • CVE-2026-15360CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.