CWE-89
20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,927)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Free Hospital Management System For Small Practices Project 1Free Hospital Management System For Small Practices Jun 17, 2026 Aug 21, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been rated as critical. This issue affects some unknown processing of the file \vm\patient\booking-complete.php....Show more |
1Free Hospital Management System For Small Practices Project 1Free Hospital Management System For Small Practices Jun 17, 2026 Aug 21, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /patient/appointment.php. The man...Show more |
1Free Hospital Management System For Small Practices Project 1Free Hospital Management System For Small Practices Jun 17, 2026 Aug 20, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the a...Show more |
1Inventory Management System Project 1Inventory Management System Jun 17, 2026 Aug 20, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/ajax/search_sales_report.php. The ma...Show more |
1Inventory Management System Project 1Inventory Management System Jun 17, 2026 Aug 20, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file app/ajax/search_sell_paymen_report.php. The manipulation of the...Show more |
1Inventory Management System Project 1Inventory Management System Jun 17, 2026 Aug 20, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Inventory Management System 1.0. This issue affects some unknown processing of the file app/action/edit_update.php. The manipulation of...Show more |
SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via theID parameter in the fulldelete.php component. |
Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to in...Show more |
1Credit Lite Project 1Credit Lite Jun 17, 2026 Aug 18, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. Affected by this vulnerability is an unknown functionality of the file /portal/reports/account_statement of the component POST Request Han...Show more |
1Online Travel Agency System Project 1Online Travel Agency System Jun 17, 2026 Aug 17, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php. |
1Online Travel Agency System Project 1Online Travel Agency System Jun 17, 2026 Aug 17, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php. |
1Online Travel Agency System Project 1Online Travel Agency System Jun 17, 2026 Aug 17, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php. |
1Online Travel Agency System Project 1Online Travel Agency System Jun 17, 2026 Aug 17, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php. |
1Online Travel Agency System Project 1Online Travel Agency System Jun 17, 2026 Aug 17, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php. |
1Online Travel Agency System Project 1Online Travel Agency System Jun 17, 2026 Aug 17, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php. |
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions. |
SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the edit.php component. |
1Cisco 1Unified Communications Manager Jun 17, 2026 Aug 16, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated...Show more |
In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue. |
1Yarpp 2Yarpp Yet Another Related Posts PluginJun 17, 2026 Aug 16, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL I...Show more |