← Back
CWE-89

20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,927)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webchess Project
1Webchess
Jun 17, 2026
Aug 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled...Show more
webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation.Show less
1Schoolmate Project
1Schoolmate
Jun 17, 2026
Aug 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parameters at DeleteFunctions.php.
1Doctor Appointment System Project
1Doctor Appointment System
Jun 17, 2026
Aug 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by...Show more
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that this originates from $_SESSION["userid"]=$_POST["userid"] at line 68 in doctors\doctorlogin.php, where userid under POST is not a session variable controlled by the server.Show less
1Mohammad Ajazuddin
1Evotingsystem Php
Jun 17, 2026
Aug 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection vulnerability in eVotingSystem-PHP v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the user input fields.
1Mitel
2Mivoice Office 400
Mivoice Office 400 Smb Controller Firmware
Jun 17, 2026
Aug 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and managemen...Show more
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.Show less
1Xxyopen
1Novel Plus
Jul 9, 2026
Aug 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
1Pearadmin
1Pear Admin Think
Jun 17, 2026
Aug 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.
1Cskaza
1Cszcms
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL Injection vulnerability in cskaza cszcms version 1.2.9, allows attackers to gain sensitive information via pm_sendmail parameter in csz_model.php.
1School Faculty Scheduling System Project
1School Faculty Scheduling System
Jun 17, 2026
Aug 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id para...Show more
SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.Show less
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Aug 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.
3Debian
PostgresqlRedhat
4Debian Linux
Enterprise LinuxPostgresql+1 more
Sep 30, 2026
Aug 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has instal...Show more
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.Show less
1Snowsoftware
1Snow License Manager
Jun 17, 2026
Aug 11, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
1Genians
2Genian Nac
Genian Ztna
Jun 17, 2026
Aug 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NA...Show more
Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from V5.0.0 through V5.0.42 (Revision 117460); Genian NAC Suite V5.0: from V5.0.0 through V5.0.54; Genian ZTNA: from V6.0.0 through V6.0.15. Show less
1Idreamsoft
1Icms
Jul 9, 2026
Aug 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
1Idreamsoft
1Icms
Jul 9, 2026
Aug 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
1Phpjabbers
1Document Creator
Jun 17, 2026
Aug 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
1Online Hospital Management System Project
1Online Hospital Management System
Jun 17, 2026
Aug 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly val...Show more
Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password fields during the login process, enabling an attacker to inject malicious SQL code.Show less
1Sherlock
1Gym Management System
Jun 17, 2026
Aug 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insu...Show more
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.Show less
1Sciencelogic
1Sl1
Jun 17, 2026
Aug 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary...Show more
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.Show less
1Sciencelogic
1Sl1
Jun 17, 2026
Aug 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arb...Show more
A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.Show less