← Back
CWE-89

20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,927)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webkul
1Qloapps
Jun 17, 2026
Jun 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mecha...Show more
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.Show less
1Inspireui
1Mstore Api
Jun 17, 2026
Jun 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauth. SQL Injection (SQLi) vulnerability in InspireUI MStore API plugin <= 3.9.7 versions.
1Game Result Matrix System Project
1Game Result Matrix System
Jun 17, 2026
Jun 23, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, was found in SourceCodester Game Result Matrix System 1.0. This affects an unknown part of the file /dipam/athlete-profile.php of the component GET Parameter Handler. Th...Show more
A vulnerability, which was classified as critical, was found in SourceCodester Game Result Matrix System 1.0. This affects an unknown part of the file /dipam/athlete-profile.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232239.Show less
1Moodle
1Moodle
Jun 17, 2026
Jun 22, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
1Monetdb
1Monetdb
Jun 17, 2026
Jun 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in the rel_deps component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
1Monetdb
1Monetdb
Jun 17, 2026
Jun 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in the __nss_database_lookup component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
1Monetdb
1Monetdb
Jun 17, 2026
Jun 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in the rel_sequences component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
1Rapidload
1Rapidload Power Up For Autoptimize
Jun 17, 2026
Jun 22, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 versions.
1Jeesite
1Jeesite
Jun 17, 2026
Jun 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml.
1Enrollment System Project
1Enrollment System
Jun 17, 2026
Jun 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate u...Show more
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.Show less
1Agro School Management System Project
1Agro School Management System
Jun 17, 2026
Jun 21, 2023
N/A· v4
7.5 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file exam-delete.php. The manipulation of th...Show more
A vulnerability has been found in code-projects Agro-School Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file exam-delete.php. The manipulation of the argument test_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232015.Show less
1Online School Fees System Project
1Online School Fees System
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in SourceCodester Online School Fees System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ajx.php of the component GET Parameter Handler. The m...Show more
A vulnerability was found in SourceCodester Online School Fees System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ajx.php of the component GET Parameter Handler. The manipulation of the argument name_startsWith leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232016.Show less
1Adiscon
1Loganalyzer
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
1Phpok
1Phpok
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
1Phpmywind
1Phpmywind
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.
1Joyplus Cms Project
1Joyplus Cms
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.
1Opencart
1Opencart
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.
1Marksoft
1Marksoft
Jun 17, 2026
Jun 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection. This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.
1Themefic
1Ultimate Addons For Contact Form 7
Jun 17, 2026
Jun 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.