CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,856)
page 219 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-52874 | Hig | 0.58 | 8.8 | 0.10 | May 22, 2025 | In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks. | ||
| CVE-2025-46337 | Cri | 0.58 | 10.0 | 0.01 | May 1, 2025 | ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a… | ||
| CVE-2024-8309 | Cri | 0.58 | 9.8 | 0.14 | Oct 29, 2024 | A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in… | ||
| CVE-2024-38814 | Hig | 0.58 | 8.8 | 0.15 | Oct 16, 2024 | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX… | ||
| CVE-2024-35584 | Hig | 0.58 | 8.8 | 0.06 | Oct 15, 2024 | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the… | ||
| CVE-2024-9379 | Med | 0.58 | 6.5 | 0.44 | KEV | Oct 8, 2024 | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements. | |
| CVE-2024-42417 | Hig | 0.58 | 8.8 | 0.07 | Oct 3, 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product. | ||
| CVE-2024-42561 | Hig | 0.58 | 8.8 | 0.09 | Aug 20, 2024 | Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php. | ||
| CVE-2024-39309 | Cri | 0.58 | 9.8 | 0.20 | Jul 1, 2024 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection… | ||
| CVE-2024-6028 | Cri | 0.58 | 9.8 | 0.12 | Jun 25, 2024 | The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | ||
| CVE-2024-36412 | Cri | 0.58 | 10.0 | 0.06 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | ||
| CVE-2024-4295 | Cri | 0.58 | 9.8 | 0.10 | Jun 5, 2024 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | ||
| CVE-2024-4443 | Cri | 0.58 | 9.8 | 0.10 | May 22, 2024 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter… | ||
| CVE-2024-32888 | Cri | 0.58 | 10.0 | 0.01 | May 15, 2024 | The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using… | ||
| CVE-2024-34032 | Hig | 0.58 | 8.8 | 0.09 | May 3, 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed. | ||
| CVE-2024-25574 | Hig | 0.58 | 8.8 | 0.09 | Apr 1, 2024 | SQL injection vulnerability exists in GetDIAE_usListParameters. | ||
| CVE-2024-30491 | Hig | 0.58 | 8.5 | 0.32 | Mar 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. | ||
| CVE-2024-28040 | Hig | 0.58 | 8.8 | 0.08 | Mar 21, 2024 | SQL injection vulnerability exists in GetDIAE_astListParameters. | ||
| CVE-2024-23975 | Hig | 0.58 | 8.8 | 0.08 | Mar 21, 2024 | SQL injection vulnerability exists in GetDIAE_slogListParameters. | ||
| CVE-2024-23494 | Hig | 0.58 | 8.8 | 0.08 | Mar 21, 2024 | SQL injection vulnerability exists in GetDIAE_unListParameters. |
- risk 0.58cvss 8.8epss 0.10
In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.
- risk 0.58cvss 10.0epss 0.01
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a…
- risk 0.58cvss 9.8epss 0.14
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in…
- risk 0.58cvss 8.8epss 0.15
An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX…
- risk 0.58cvss 8.8epss 0.06
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the…
- risk 0.58cvss 6.5epss 0.44
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
- risk 0.58cvss 8.8epss 0.07
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.
- risk 0.58cvss 8.8epss 0.09
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.
- risk 0.58cvss 9.8epss 0.20
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection…
- risk 0.58cvss 9.8epss 0.12
The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
- risk 0.58cvss 10.0epss 0.06
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
- risk 0.58cvss 9.8epss 0.10
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
- risk 0.58cvss 9.8epss 0.10
The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter…
- risk 0.58cvss 10.0epss 0.01
The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using…
- risk 0.58cvss 8.8epss 0.09
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.
- risk 0.58cvss 8.8epss 0.09
SQL injection vulnerability exists in GetDIAE_usListParameters.
- risk 0.58cvss 8.5epss 0.32
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.
- risk 0.58cvss 8.8epss 0.08
SQL injection vulnerability exists in GetDIAE_astListParameters.
- risk 0.58cvss 8.8epss 0.08
SQL injection vulnerability exists in GetDIAE_slogListParameters.
- risk 0.58cvss 8.8epss 0.08
SQL injection vulnerability exists in GetDIAE_unListParameters.