CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,866 vulnerabilities with CWE-89
CVE-2018-20018
HIGH
S-CMS V3.0 - SQL Injection via S_id Parameter
CVSS 7.5
CVE-2018-7065
HIGH
Aruba ClearPass Policy Manager < 6.6.10 - Authenticated SQL Injection
CVSS 7.2
CVE-2018-19925
CRITICAL
Sales & Company Management System < 2018-06-06 - SQL Injection via Member Order Type Parameter
CVSS 9.8
CVE-2018-19898
HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via Article Edit Post Parameter
CVSS 8.8
CVE-2018-19897
HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via listorders[key][1] Parameter
CVSS 7.2
CVE-2018-19896
HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via SlideController ids[] Parameter
CVSS 7.2
CVE-2018-19895
HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via parentid Parameter in Nav Action
CVSS 7.2
CVE-2018-19894
HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via CommentadminController ids[] Parameter
CVSS 7.2
CVE-2018-19893
CRITICAL
PbootCMS 1.2.1 - SQL Injection via SearchController.php Query String
CVSS 9.8
CVE-2018-1002000
HIGH
WordPress Arigato Autoresponder & Newsletter <v2.5.1.8 - SQL Injection
CVSS 7.2
CVE-2018-18619
CRITICAL
Advanced Comment System 1.0 - SQL Injection via Page Parameter
CVSS 9.8
CVE-2018-15441
CRITICAL
Cisco Prime License Manager 11.0.1-11.5 - Unauthenticated SQL Injection via HTTP POST Request
CVSS 9.4
CVE-2018-13350
CRITICAL
TerraMaster TOS 3.1.03 - SQL Injection via Event Parameter
CVSS 9.8
CVE-2018-18982
HIGH
NUUO CMS < 3.3 - SQL Injection
CVSS 8.8
CVE-2018-19559
CRITICAL
CuppaCMS <2018-11-12 - SQL Injection
CVSS 9.8
CVE-2018-19558
CRITICAL
arcms < 2018-03-19 - SQL Injection via Newslist Limit Parameter
CVSS 9.8
CVE-2018-19557
CRITICAL
arcms <2018-03-19 - Info Disclosure
CVSS 9.8
CVE-2018-19553
HIGH
Interspire Email Marketer <6.1.6 - SQL Injection
CVSS 8.8
CVE-2018-19552
HIGH
Interspire Email Marketer <6.1.6 - SQL Injection
CVSS 8.8
CVE-2018-19551
HIGH
Interspire Email Marketer <6.1.6 - SQL Injection
CVSS 8.8
CVE-2018-19549
HIGH
Interspire Email Marketer <6.1.6 - SQL Injection
CVSS 8.8
CVE-2018-19468
CRITICAL
HuCart 5.7.4 - SQL Injection via X-Forwarded-For Header
CVSS 9.8
CVE-2018-19436
HIGH
webERP 4.15 - SQL Injection via Manufacturing CollectiveWorkOrderCost.php SearchParts Parameter
CVSS 7.2
CVE-2018-19435
HIGH
webERP 4.15 - SQL Injection via SalesInquiry.php SortBy Parameter
CVSS 7.2
CVE-2018-19434
HIGH
webERP 4.15 - SQL Injection via BankMatching.php AmtClear_ Parameter
CVSS 7.2
Details
Vulnerabilities
19,866
Exploit Likelihood
High