CWE-89
20,923 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,923)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Internship Management System Project 1Online Internship Management System Jun 17, 2026 May 11, 2023 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in SourceCodester Online Internship Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/login.php of the component POST P...Show more |
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). |
1Online Tours & Travels Management System Project 1Online Tours & Travels Management System Jun 17, 2026 May 10, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects the function exec of the file disapprove_delete.php. The manipulation of the argum...Show more |
1Veritas 1Infoscale Operations Manager Jun 17, 2026 May 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. T...Show more |
2Janobe Online Reviewer System Project2Online Reviewer System Online Reviewer SystemJun 17, 2026 May 9, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update....Show more |
1Oretnom23 1Establishment Billing Management System Jun 17, 2026 May 9, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability has been found in SourceCodester Billing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file ajax_service.php of the component POST Par...Show more |
1Oretnom23 1Food Ordering Management System Jun 17, 2026 May 9, 2023 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability, which was classified as critical, was found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the component Registration. The manipulation of the argument username...Show more |
1Online Pizza Ordering System Project 1Online Pizza Ordering System Jun 17, 2026 May 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter. |
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query. |
1Coinmarketstats 1Bitcoin / Altcoin Payment Gateway For Woocommerce Jun 17, 2026 May 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injec...Show more |
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php. |
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request. |
SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the database were properly escaped for SQL injection. This has been the case since at least version 0.9.0(rele...Show more |
1Judging Management System Project 1Judging Management System Jun 17, 2026 May 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=. |
1Php Login Project 1Php Login Nov 21, 2024 May 6, 2023 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in PHP-Login 1.0. It has been declared as critical. This vulnerability affects the function checkLogin of the file login/scripts/class.loginscript.php of the component POST Parameter Handler. Th...Show more |
1Netentsec 1Application Security Gateway Jul 9, 2026 May 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information. |
1Netentsec 1Application Security Gateway Jul 9, 2026 May 5, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php. |
1Judging Management System Project 1Judging Management System Jun 17, 2026 May 4, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php. |
1Catontechnology 1Ctp Relay Server Jun 17, 2026 May 4, 2023 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been found in Caton CTP Relay Server 1.2.9 and classified as critical. This vulnerability affects unknown code of the file /server/api/v1/login of the component API. The manipulation of the argument u...Show more |
IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL opera...Show more |