VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 319 of 1,043
  • CVE-2022-29411HigApr 28, 2022
    risk 0.54cvss 8.3epss 0.01

    SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id).

  • CVE-2021-23405HigJul 9, 2021
    risk 0.54cvss 8.3epss 0.02

    This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.

  • CVE-2019-15984HigJan 6, 2020
    risk 0.54cvss 7.2epss 0.47

    Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative…

  • CVE-2019-12372HigMay 28, 2019
    risk 0.54cvss 7.8epss 0.01

    Petraware pTransformer ADC before 2.1.7.22827 allows SQL Injection via the User ID parameter to the login form.

  • CVE-2018-17283HigSep 21, 2018
    risk 0.54cvss 7.5epss 0.66

    Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or…

  • CVE-2015-4669HigSep 25, 2017
    risk 0.54cvss 7.8epss 0.01

    The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.

  • CVE-2026-18137HigSep 22, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.

  • CVE-2026-79752CriSep 17, 2026
    risk 0.53cvss —epss 0.01

    CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType,…

  • CVE-2026-84813CriSep 3, 2026
    risk 0.53cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

  • CVE-2026-80236HigAug 26, 2026
    risk 0.53cvss 8.2epss 0.00

    Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents.

  • CVE-2026-77635CriAug 24, 2026
    risk 0.53cvss —epss 0.00

    CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This…

  • CVE-2026-76205HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling…

  • CVE-2026-70422HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script…

  • CVE-2026-18230HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL…

  • CVE-2026-18057HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to…

  • CVE-2026-16977HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.

  • CVE-2026-17017HigAug 9, 2026
    risk 0.53cvss 8.1epss 0.00

    The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to…

  • CVE-2026-15361HigAug 7, 2026
    risk 0.53cvss 8.1epss 0.00

    The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection…

  • CVE-2026-52521HigAug 3, 2026
    risk 0.53cvss 8.1epss 0.00

    A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.

  • CVE-2026-16539HigAug 3, 2026
    risk 0.53cvss 8.1epss 0.00

    The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating a page, allowing users with the Editor role and above to perform SQL Injection attacks.