CWE-89
20,960 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,960)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Projectworlds 1Student Result Management System Jun 17, 2026 Dec 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_id' parameter of the add_classes.php resource does not validate the characters received and they a...Show more |
1Projectworlds 1Railway Reservation System Jun 17, 2026 Dec 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'byname' parameter of the train.php resource does not validate the characters received and they are sent unfilt...Show more |
1Projectworlds 1Railway Reservation System Jun 17, 2026 Dec 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent un...Show more |
1Projectworlds 1Railway Reservation System Jun 17, 2026 Dec 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltere...Show more |
1Projectworlds 1Leave Management System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsickleave' parameter of the admin/setleaves.php resource does not validate the characters received and t...Show more |
1Projectworlds 1Leave Management System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and t...Show more |
1Projectworlds 1Online Examination System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the /update.php?q=addquiz resource does not validate the characters received and they are sent...Show more |
1Projectworlds 1Online Examination System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the /update.php?q=quiz&step=2 resource does not validate the characters received and they are s...Show more |
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php. |
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php. |
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php. |
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php. |
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php. |
1Projectworlds 1Online Examination System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the /update.php?q=quiz resource does not validate the characters received and they are sent unfil...Show more |
1Projectworlds 1Online Examination System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the /update.php resource does not validate the characters received and they are sent unfiltere...Show more |
1Projectworlds 1Online Examination System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the /update.php?q=rmquiz resource does not validate the characters received and they are sent u...Show more |
1Projectworlds 1Online Examination System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the /update.php resource does not validate the characters received and they are sent unfilte...Show more |
1Projectworlds 1Online Examination System Jun 17, 2026 Dec 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the /update.php?q=addqns resource does not validate the characters received and they are sent un...Show more |
1Softomi 1Advanced C2c Marketplace Software Jun 17, 2026 Dec 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injecti...Show more |
1Tongda2000 1Office Anywhere Jun 17, 2026 Dec 21, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/vehicle/query/delete.php. The manipulation of the argument V...Show more |