CWE-89
20,892 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,892)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Mar 17, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Canteen Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file changeUsername.php. The manipulation of the argument...Show more |
1Online Pizza Ordering System Project 1Online Pizza Ordering System Jun 17, 2026 Mar 17, 2023 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerability affects unknown code of the file admin/ajax.php?action=login2 of the component Login Page. The manip...Show more |
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible...Show more |
1Automatic Question Paper Generator System Project 1Automatic Question Paper Generator System Jun 17, 2026 Mar 17, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/courses/view_course....Show more |
1Automatic Question Paper Generator System Project 1Automatic Question Paper Generator System Jun 17, 2026 Mar 17, 2023 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in SourceCodester Automatic Question Paper Generator System 1.0. Affected is an unknown function of the file users/user/manage_user.php of the component GET Pa...Show more |
1Medicine Tracker System Project 1Medicine Tracker System Jun 17, 2026 Mar 17, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracker System 1.0. This issue affects some unknown processing of the file medicines/view_details.php of the component GET Para...Show more |
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, quoting is not done properly in UUID DAO model. There is the theoretical possibility to inject custom SQL if the developer is u...Show more |
1School Registration And Fee System Project 1School Registration And Fee System Jun 17, 2026 Mar 16, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php. |
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint. |
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint. |
Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php |
1Online Book Store Project Project 1Online Book Store Project Jun 17, 2026 Mar 16, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. |
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter. |
1Code Projects 1Simple Art Gallery Jun 17, 2026 Mar 15, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in Simple Art Gallery 1.0. Affected is an unknown function of the file adminHome.php. The manipulation of the argument social_facebook leads to sql injection. It is p...Show more |
1Friendly Island Pizza Website And Ordering System Project 1Friendly Island Pizza Website And Ordering System Jun 17, 2026 Mar 15, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file addmem.php of the component POST Pa...Show more |
1Richplugins 1Plugin For Google Reviews Jun 17, 2026 Mar 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. |
1Oretnom23 1Simple Customer Relationship Management System Jun 17, 2026 Mar 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function. |
1Oretnom23 1Simple Customer Relationship Management System Jun 17, 2026 Mar 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function. |
1Oretnom23 1Simple Customer Relationship Management System Jun 17, 2026 Mar 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function. |