CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,881 vulnerabilities with CWE-89
CVE-2018-1674 MEDIUM
IBM Business Process Manager <18.0.0.1 - SQL Injection
CVSS 6.3
CVE-2018-17254 CRITICAL
JCK Editor 6.4.4 - SQL Injection via jtreelink Parent Parameter
CVSS 9.8
CVE-2018-17243 CRITICAL
Zoho ManageEngine OpManager <12.3-123205 - SQL Injection
CVSS 9.8
CVE-2018-17232 CRITICAL
Slack ArchiveBot <2018-09-19 - SQL Injection
CVSS 9.8
CVE-2018-17136 CRITICAL
zzcms 8.3 - SQL Injection via Client-Ip HTTP Header
CVSS 9.8
CVE-2018-17129 MEDIUM
MetInfo 6.1.0 - SQL Injection via class1 Field in doexport()
CVSS 4.9
CVE-2018-17110 CRITICAL
Simple POS 4.0.24 - SQL Injection via Management Panel Search Parameter
CVSS 9.8
CVE-2018-17092 MEDIUM
DonLinkage 6.6.8 - Authenticated SQL Injection via Proxy PHP Endpoints
CVSS 5.4
CVE-2018-17035 CRITICAL
UCMS 1.4.6 - SQL Injection via Install Index.php mysql_dbname Parameter
CVSS 9.8
CVE-2018-16389 MEDIUM
e107 2.1.8 - SQL Injection via banlist.php old_ip Parameter
CVSS 6.5
CVE-2018-3885 HIGH
ERPNext 10.1.6 - Authenticated SQL Injection via order_by Parameter
CVSS 8.8
CVE-2018-3884 HIGH
ERPNext v10.1.6 - Authenticated SQL Injection via sort_by and start Parameters
CVSS 8.8
CVE-2018-3883 HIGH
ERPNext 10.1.6 - Authenticated SQL Injection via Employee and Sort Order Parameters
CVSS 8.8
CVE-2018-3882 HIGH
ERPNext v10.1.6 - Authenticated SQL Injection via Searchfield Parameter
CVSS 8.8
CVE-2018-16762 CRITICAL
FUEL CMS < 1.4.2 - SQL Injection via layout, published, or search_term parameter
CVSS 9.8
CVE-2018-16724 CRITICAL
baijiacms V4 - Blind SQL Injection via Order Parameter
CVSS 9.8
CVE-2018-1756 HIGH
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 - SQL Injection
CVSS 7.5
CVE-2018-15918 MEDIUM
Jorani 0.6.5 - SQL Injection via Startdate or Enddate Parameter
CVSS 5.4
CVE-2018-16436 HIGH
gxlcms 2.0 - Authenticated SQL Injection
CVSS 7.2
CVE-2018-16445 CRITICAL
SeaCMS < 6.61 - SQL Injection via tid Parameter
CVSS 9.8
CVE-2018-16432 CRITICAL
BlueCMS 1.6 - SQL Injection via user_name Parameter
CVSS 9.8
CVE-2018-16410 MEDIUM
Vanilla < 2.6.1 - SQL Injection via InvitationID Array to DeleteInvitation Endpoint
CVSS 6.5
CVE-2018-16385 CRITICAL
ThinkPHP < 5.1.23 - SQL Injection via Query String
CVSS 9.8
CVE-2018-16384 HIGH
OWASP ModSecurity Core Rule Set <= 3.1.0-rc3 - SQL Injection via PL1 Bypass with Special Function Names
CVSS 7.5
CVE-2018-16354 CRITICAL
FHCRM < 2018-02-11 - SQL Injection via User Read Limit Parameter
CVSS 9.8
Details
Vulnerabilities 19,881
Exploit Likelihood High