CWE-89
20,900 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,900)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Purchase Order Management Project 1Purchase Order Management Jun 17, 2026 Apr 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php. |
1Auto Dealer Management System Project 1Auto Dealer Management System Jul 9, 2026 Apr 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability. |
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form. |
lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php. |
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1. |
Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions. |
1Idnovate 1Popup Module (on Entering, Exit Popup, Add Product) And Newsletter Jun 17, 2026 Apr 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(). |
1Oretnom23 1Online Computer And Laptop Store Jun 17, 2026 Apr 11, 2023 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is the function update_order_status of the file /classes/Master.php?f=updat...Show more |
1Oretnom23 1Online Computer And Laptop Store Jun 17, 2026 Apr 11, 2023 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. Affected is the function delete_order of the file /classes/master.php?f=delete_order. The manipulation...Show more |
1Oretnom23 1Online Computer And Laptop Store Jun 17, 2026 Apr 11, 2023 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. This issue affects the function save_brand of the file /classes/Master.php?f=save_brand. The manip...Show more |
1Complaint Management System Project 1Complaint Management System Jun 17, 2026 Apr 11, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in SourceCodester Complaint Management System 1.0. This vulnerability affects unknown code of the file /users/check_availability.php of the component POST Parameter Handle...Show more |
1Sales Tracker Management System Project 1Sales Tracker Management System Jun 17, 2026 Apr 11, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/products/manage_product.php of the c...Show more |
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x and 3.0.x allows a rem...Show more |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating t...Show more |
1Vivwebsolutions 1Dynamic Widgets Nov 27, 2024 Apr 10, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in Dynamic Widgets Plugin up to 1.5.10 on WordPress. This issue affects some unknown processing of the file classes/dynwid_class.php. The manipulation lea...Show more |
1Oretnom23 1Online Eyewear Shop Jun 17, 2026 Apr 10, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file /admin/inventory/manage_stock.php of the component GET Parameter Handler. Th...Show more |
1Save Your Carts And Buy Later Or Send It Project 1Save Your Carts And Buy Later Or Send It Jun 17, 2026 Apr 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component. |
1Tailor Management System Project 1Tailor Management System Jun 17, 2026 Apr 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the customer parameter of the orderadd.php file |
1Codepeople 1Cp Appointment Calendar Nov 21, 2024 Apr 10, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipu...Show more |
A vulnerability was found in HD FLV PLayer Plugin up to 1.7 on WordPress. It has been rated as critical. Affected by this issue is the function hd_add_media/hd_update_media of the file functions.php. The manipulation of...Show more |