VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 359 of 1,043
  • CVE-2018-10736HigMay 16, 2018
    risk 0.50cvss 7.2epss 0.42

    A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

  • CVE-2018-10735HigMay 16, 2018
    risk 0.50cvss 7.2epss 0.42

    A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.

  • CVE-2015-7714HigOct 18, 2017
    risk 0.50cvss 7.2epss 0.02

    Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6)…

  • CVE-2017-8377HigMay 1, 2017
    risk 0.50cvss 8.8epss 0.01

    GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.

  • CVE-2017-6088HigApr 11, 2017
    risk 0.50cvss 7.2epss 0.06

    Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5)…

  • CVE-2017-6098HigFeb 21, 2017
    risk 0.50cvss 7.2epss 0.05

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.

  • CVE-2017-6097HigFeb 21, 2017
    risk 0.50cvss 7.2epss 0.05

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.

  • CVE-2017-6096HigFeb 21, 2017
    risk 0.50cvss 7.2epss 0.05

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.

  • CVE-2016-3072HigJun 7, 2016
    risk 0.50cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.

  • CVE-2026-105856HigOct 6, 2026
    risk 0.49cvss —epss 0.00

    Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can inject SQL through a crafted field…

  • CVE-2026-102796HigSep 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5,…

  • CVE-2015-20122HigSep 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication.…

  • CVE-2026-84239HigSep 18, 2026
    risk 0.49cvss 7.6epss 0.01

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

  • CVE-2021-48008HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization…

  • CVE-2019-25776HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile plugin endpoint. Attackers can bypass space-based filter…

  • CVE-2026-85705HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2026-18442HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.01

    The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and…

  • CVE-2026-15275HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2026-66631HigSep 17, 2026
    risk 0.49cvss 7.6epss 0.00

    Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

  • CVE-2026-66630HigSep 17, 2026
    risk 0.49cvss 7.6epss 0.00

    Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.