CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,913 vulnerabilities with CWE-89
CVE-2015-20120 HIGH
RealtyScript 4.0.2 Multiple Time-based Blind SQL Injection
CVSS 8.2
CVE-2015-10147 MEDIUM
Easy Testimonial Slider & Form <1.0.2 - SQL Injection
CVSS 4.9
CVE-2015-10146 MEDIUM
Thumbnail Slider With Lightbox <1.0.4 - SQL Injection
CVSS 4.9
CVE-2015-0842 CRITICAL
yubiserver < 0.6 - SQL Injection
CVSS 9.8
CVE-2015-10126 MEDIUM
Easy2Map Photos Plugin 1.0.1 - WordPress - SQL Injection
CVSS 6.3
CVE-2015-10124 MEDIUM
Most Popular Posts Widget Plugin <0.9 - SQL Injection
CVSS 6.3
CVE-2015-10122 MEDIUM
wp-donate Plugin <1.4 - SQL Injection
CVSS 6.3
CVE-2015-10111 MEDIUM
Watu Quiz Plugin <2.6.8 - SQL Injection
CVSS 6.3
CVE-2015-10106 MEDIUM
mback2k mh_httpbl Extension <1.1.7 - SQL Injection
CVSS 6.3
CVE-2015-10100 MEDIUM
Dynamic Widgets Plugin <1.5.11 - SQL Injection
CVSS 6.3
CVE-2015-10099 MEDIUM
CP Appointment Calendar Plugin <1.1.5 - SQL Injection
CVSS 6.3
CVE-2015-10097 MEDIUM
grinnellplans-php <3.0 - SQL Injection
CVSS 6.3
CVE-2015-10091 MEDIUM
ByWater Solutions bywater-koha-xslt - SQL Injection
CVSS 4.7
CVE-2015-10086 HIGH
OpenCycleCompass server-php - SQL Injection
CVSS 7.3
CVE-2015-10084 MEDIUM
Irontec klear-library chloe - SQL Injection
CVSS 5.5
CVE-2015-10077 MEDIUM
webbuilders-group silverstripe-kapost-bridge <0.4.0 - SQL Injection
CVSS 6.3
CVE-2015-10076 MEDIUM
dimtion Shaarlier <1.2.2 - SQL Injection
CVSS 5.5
CVE-2015-10070 MEDIUM
twiddit < 2015-03-18 - SQL Injection in index.php
CVSS 6.3
CVE-2015-10069 MEDIUM
viakondratiuk cash-machine - SQL Injection
CVSS 5.5
CVE-2015-10068 MEDIUM
movify-j < 2015-03-14 - SQL Injection via ReviewServiceImpl getByMovieId Function
CVSS 5.5
CVE-2015-10066 MEDIUM
wuersch < 2015-03-27 - SQL Injection via packValue/getByCustomQuery Function
CVSS 5.5
CVE-2015-10064 MEDIUM
VictorFerraresi pokemon-database-php - SQL Injection
CVSS 5.5
CVE-2015-10063 HIGH
saemorris TheRadSystem - SQL Injection
CVSS 7.3
CVE-2015-10061 MEDIUM
evandro-machado Trabalho-Web2 - SQL Injection
CVSS 5.5
CVE-2015-10060 MEDIUM
mnbikeways_database < 2015-06-22 - SQL Injection via id1/id2 Argument
CVSS 5.5
Details
Vulnerabilities 19,913
Exploit Likelihood High