CWE-89
20,889 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,889)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. |
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. |
jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPACS allows SQL Injection.
This issue affects MedDataPACS : before 2023-03-03. |
1Bywatersolutions 1Bywater Koha Xslt Nov 21, 2024 Mar 6, 2023 N/A· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability has been found in ByWater Solutions bywater-koha-xslt and classified as critical. This vulnerability affects the function StringSearch of the file admin/systempreferences.pl. The manipulation of the argum...Show more |
1Flashgames Project 1Flashgames Nov 21, 2024 Mar 5, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in iGamingModules flashgames 1.1.0. It has been classified as critical. Affected is an unknown function of the file game.php. The manipulation of the argument lid leads to sql injection. It is p...Show more |
A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the a...Show more |
1Judging Management System Project 1Judging Management System Jun 17, 2026 Mar 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php. |
1Judging Management System Project 1Judging Management System Jun 17, 2026 Mar 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php. |
1Judging Management System Project 1Judging Management System Jun 17, 2026 Mar 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php. |
A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown part of the file /api/admin/system/store/order/list. The manipulation of the argument keywords leads t...Show more |
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function. |
1Lionfish Cms Project 1Lionfish Cms Jun 17, 2026 Mar 2, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function goods_detail of the file ApiController.class.php. The manipulation of the argument goods_id leads to sql...Show more |
CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15. |
1Electronic Medical Records System Project 1Electronic Medical Records System Jun 17, 2026 Mar 2, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Electronic Medical Records System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file administrator.php of the compone...Show more |
1Computer Parts Sales And Inventory System Project 1Computer Parts Sales And Inventory System Jun 17, 2026 Mar 1, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file processlogin. The manipulation of the argument user l...Show more |
The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be...Show more |
1Uzaybaskul 1Weighbridge Automation Software Jun 17, 2026 Mar 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software:...Show more |
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to syste...Show more |