VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 567 of 1,044
  • CVE-2017-6573HigMar 9, 2017
    risk 0.47cvss 7.2epss 0.02

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id.

  • CVE-2017-6572HigMar 9, 2017
    risk 0.47cvss 7.2epss 0.02

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.

  • CVE-2017-6571HigMar 9, 2017
    risk 0.47cvss 7.2epss 0.02

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.

  • CVE-2017-6570HigMar 9, 2017
    risk 0.47cvss 7.2epss 0.02

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.

  • CVE-2017-6492HigMar 5, 2017
    risk 0.47cvss 7.2epss 0.01

    SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.

  • CVE-2017-5347HigJan 12, 2017
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.

  • CVE-2016-1000122HigOct 27, 2016
    risk 0.47cvss 7.2epss 0.02

    XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension

  • CVE-2016-1000120HigOct 27, 2016
    risk 0.47cvss 7.2epss 0.02

    SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla

  • CVE-2016-1000119HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla

  • CVE-2016-1000118HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    XSS & SQLi in HugeIT slideshow v1.0.4

  • CVE-2016-1000117HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    XSS & SQLi in HugeIT slideshow v1.0.4

  • CVE-2016-1000116HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.02

    Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS

  • CVE-2016-1000115HigOct 21, 2016
    risk 0.47cvss 7.2epss 0.03

    Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS

  • CVE-2016-2174HigJun 13, 2016
    risk 0.47cvss 7.2epss 0.02

    SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.

  • CVE-2016-4040HigApr 19, 2016
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.

  • CVE-2006-5738HigNov 6, 2006
    risk 0.47cvss 7.2epss 0.01

    Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2026-107384HigOct 8, 2026
    risk 0.46cvss 8.1epss 0.00

    MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause…

  • CVE-2026-62251HigOct 7, 2026
    risk 0.46cvss 8.1epss 0.00

    Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any…

  • CVE-2026-54596HigSep 17, 2026
    risk 0.46cvss 8.1epss 0.00

    ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the frequency parameter handled by…

  • CVE-2026-54354HigSep 17, 2026
    risk 0.46cvss 8.2epss 0.01

    MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE POSTGIS and metadata such as…