← Back
CWE-89

20,889 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,889)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Catering Reservation System Project
1Online Catering Reservation System
Jun 17, 2026
Feb 28, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. This affects an unknown part of the file /reservation/add_message.php of the component POST Parameter Handle...Show more
A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. This affects an unknown part of the file /reservation/add_message.php of the component POST Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222003.Show less
1Online Student Management System Project
1Online Student Management System
Jun 17, 2026
Feb 28, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in SourceCodester Online Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file eduauth/edit-class-detail.php. The manipul...Show more
A vulnerability was found in SourceCodester Online Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file eduauth/edit-class-detail.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-222002 is the identifier assigned to this vulnerability.Show less
1Online Reviewer Management System Project
1Online Reviewer Management System
Jun 17, 2026
Feb 28, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.ph...Show more
An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.php.Show less
1Server Php Project
1Server Php
Nov 21, 2024
Feb 28, 2023
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability, which was classified as critical, was found in OpenCycleCompass server-php. Affected is an unknown function of the file api1/login.php. The manipulation of the argument user leads to sql injection. It is...Show more
A vulnerability, which was classified as critical, was found in OpenCycleCompass server-php. Affected is an unknown function of the file api1/login.php. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The name of the patch is fa0d9bcf81c711a88172ad0d37a842f029ac3782. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-221808.Show less
1Spip
1Spip
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
1Domoticalabs
1Ikon Server
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.
1Oretnom23
1Simple Customer Relationship Management System
Jun 17, 2026
Feb 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function.
1Oretnom23
1Simple Customer Relationship Management System
Jun 17, 2026
Feb 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.
1Oretnom23
1Simple Customer Relationship Management System
Jun 17, 2026
Feb 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.
1Oretnom23
1Simple Customer Relationship Management System
Jun 17, 2026
Feb 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.
1Oretnom23
1Simple Customer Relationship Management System
Jun 17, 2026
Feb 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.
1Phpgurukul
1Art Gallery Management System
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
1Phpgurukul
1Art Gallery Management System
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.
1Premio
1My Sticky Elements
Jun 17, 2026
Feb 27, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege u...Show more
The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as adminShow less
1Davinci Project
1Davinci
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.
1Aremis
1Aremis 4 Nomads
Jun 17, 2026
Feb 27, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It allows SQL Injection, by which an attacker can bypass authentication and retrieve data that is stored in the database.
1Doctor's Appointment System Project
1Doctor's Appointment System
Jun 17, 2026
Feb 27, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been found in SourceCodester Doctors Appointment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/patient.php of the component Param...Show more
A vulnerability has been found in SourceCodester Doctors Appointment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/patient.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221827.Show less
1Doctor's Appointment System Project
1Doctor's Appointment System
Jun 17, 2026
Feb 27, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, was found in SourceCodester Doctors Appointment System 1.0. Affected is an unknown function of the file /admin/add-new.php of the component Parameter Handler. The manipu...Show more
A vulnerability, which was classified as critical, was found in SourceCodester Doctors Appointment System 1.0. Affected is an unknown function of the file /admin/add-new.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221826 is the identifier assigned to this vulnerability.Show less
1Doctor's Appointment System Project
1Doctor's Appointment System
Jun 17, 2026
Feb 27, 2023
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown processing of the file /admin/edit-doc.php. The manipulation of the argu...Show more
A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown processing of the file /admin/edit-doc.php. The manipulation of the argument email/oldmail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Doctor's Appointment System Project
1Doctor's Appointment System
Jun 17, 2026
Feb 27, 2023
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulati...Show more
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument search/id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less