CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,911 vulnerabilities with CWE-89
CVE-2017-1002022 CRITICAL
WordPress Plugin Surveys <1.01.8 - SQL Injection
CVSS 9.8
CVE-2017-1002021 CRITICAL
WordPress Surveys <1.01.8 - SQL Injection
CVSS 9.8
CVE-2017-1002020 CRITICAL
WordPress Plugin Surveys <1.01.8 - SQL Injection
CVSS 9.8
CVE-2017-1002019 CRITICAL
WordPress Plugin Eventr <1.02.2 - SQL Injection
CVSS 9.8
CVE-2017-1002018 CRITICAL
WordPress Plugin Eventr <1.02.2 - SQL Injection
CVSS 9.8
CVE-2017-1002015 CRITICAL
WordPress Plugin Image-Gallery-With-Slideshow <1.5.2 - SQL Injection
CVSS 9.8
CVE-2017-1002014 CRITICAL
WordPress Plugin Image-Gallery-With-Slideshow <1.5.2 - SQL Injection
CVSS 9.8
CVE-2017-1002013 CRITICAL
WordPress Plugin Image Gallery With Slideshow <1.5.2 - SQL Injection
CVSS 9.8
CVE-2017-1002012 CRITICAL
WordPress Plugin Image-Gallery-With-Slideshow <1.5.2 - SQL Injection
CVSS 9.8
CVE-2017-1002010 CRITICAL
WordPress Plugin Membership Simplified <1.58 - SQL Injection
CVSS 9.8
CVE-2017-1002009 CRITICAL
WordPress Plugin Membership Simplified <1.58 - SQL Injection
CVSS 9.8
CVE-2017-1002005 HIGH
WordPress Plugin DTracker <1.5 - SQL Injection
CVSS 7.5
CVE-2017-1002004 HIGH
WordPress Plugin DTracker <1.5 - SQL Injection
CVSS 7.5
CVE-2017-14403 CRITICAL
eyesofnetwork 5.1-0 - SQL Injection via term Parameter
CVSS 9.8
CVE-2017-14402 CRITICAL
EyesOfNetwork eonweb <5.1 - SQL Injection
CVSS 9.8
CVE-2017-14401 CRITICAL
EyesOfNetwork eonweb <5.1 - SQL Injection
CVSS 9.8
CVE-2017-14396 CRITICAL
osTicket - SQL Injection via Array Parameter Syntax
CVSS 9.8
CVE-2017-8015 CRITICAL
EMC AppSync < 3.5 - SQL Injection
CVSS 9.8
CVE-2017-14345 CRITICAL
tianchoy/blog <2017-09-12 - SQL Injection
CVSS 9.8
CVE-2017-14252 CRITICAL
eyesofnetwork 5.1-0 - SQL Injection via group_id Cookie
CVSS 9.8
CVE-2017-14247 CRITICAL
EyesOfNetwork eonweb <5.1 - SQL Injection
CVSS 9.8
CVE-2017-14242 CRITICAL
Dolibarr 6.0.0 - SQL Injection via don/list.php statut Parameter
CVSS 9.8
CVE-2017-14238 CRITICAL
Dolibarr ERP/CRM <6.0.0 - SQL Injection
CVSS 9.8
CVE-2017-12731 CRITICAL
OPW SiteSentinel Integra 100/500 and iSite ATG Firmware <175 - SQL Injection
CVSS 9.8
CVE-2017-11161 CRITICAL
Synology Photo Station < 6.7.4-3433 and 6.3-2968 - SQL Injection via article_id or type Parameter
CVSS 9.8
Details
Vulnerabilities 19,911
Exploit Likelihood High