CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,881 vulnerabilities with CWE-89
CVE-2018-17852
CRITICAL
WUZHI CMS 4.1.0 - SQL Injection via groupname Parameter
CVSS 9.8
CVE-2018-17831
CRITICAL
REDAXO < 5.6.3 - SQL Injection via rex_list prepareQuery Function
CVSS 9.8
CVE-2018-17796
CRITICAL
mushroom_content_management_system < 3.1.2 - SQL Injection via FIELD_T Parameter
CVSS 9.8
CVE-2018-17575
CRITICAL
SWA SWA.JACAD 3.1.37 Build 024 - SQL Injection
CVSS 9.8
CVE-2018-17397
CRITICAL
AlphaIndex Dictionaries <1.0 - SQL Injection
CVSS 9.8
CVE-2018-17394
CRITICAL
Joomla! Timetable Schedule <3.6.8 - SQL Injection
CVSS 9.8
CVE-2018-17391
CRITICAL
Super Cms Blog Pro 1.0 - SQL Injection
CVSS 9.8
CVE-2018-17385
CRITICAL
Social Factory 3.8.3 - SQL Injection
CVSS 9.8
CVE-2018-17384
CRITICAL
Swap Factory 2.2.1 - SQL Injection via filter_order_Dir or filter_order Parameter
CVSS 9.8
CVE-2018-17383
CRITICAL
Collection Factory 4.1.9 - SQL Injection via filter_order or filter_order_Dir Parameter
CVSS 9.8
CVE-2018-17382
CRITICAL
Jobs Factory 2.0.4 - SQL Injection via filter_letter Parameter
CVSS 9.8
CVE-2018-17380
CRITICAL
Article Factory Manager 4.3.9 - SQL Injection
CVSS 9.8
CVE-2018-17379
CRITICAL
Raffle Factory 3.5.2 - SQL Injection
CVSS 9.8
CVE-2018-17378
CRITICAL
Penny Auction Factory 2.0.4 - SQL Injection
CVSS 9.8
CVE-2018-17377
CRITICAL
Questions 1.4.3 - SQL Injection via Term Userid Users or Groups Parameter
CVSS 9.8
CVE-2018-17376
CRITICAL
Joomla! Reverse Auction Factory 4.3.8 - SQL Injection
CVSS 9.8
CVE-2018-17375
CRITICAL
Music Collection 3.0.3 - SQL Injection
CVSS 9.8
CVE-2018-16659
CRITICAL
Rausoft ID.prove <2.95 - SQL Injection
CVSS 9.8
CVE-2018-14956
CRITICAL
CMS ISWEB 3.5.3 - SQL Injection
CVSS 9.8
CVE-2018-7107
HIGH
HPE Device Entitlement Gateway 3.2.4, 3.3, 3.3.1 - SQL Injection
CVSS 8.8
CVE-2018-17566
CRITICAL
ThinkPHP 5.1.24 - SQL Injection via WHERE Condition in Delete Function
CVSS 9.8
CVE-2018-17410
CRITICAL
Horus CMS - SQL Injection via /busca or /home URI
CVSS 9.8
CVE-2018-16822
CRITICAL
SeaCMS 6.64 - SQL Injection via admin_video.php order Parameter
CVSS 9.8
CVE-2018-17283
HIGH
Zoho ManageEngine OpManager <12.3 Build 123196 - SQL Injection
CVSS 7.5
CVE-2018-14592
CRITICAL
CWJoomla <2.0.7, <1.0.6 - SQL Injection
CVSS 9.8
Details
Vulnerabilities
19,881
Exploit Likelihood
High