← Back
CWE-89

20,883 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,883)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Employee Task Management System Project
1Employee Task Management System
Jun 17, 2026
Feb 18, 2023
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file edit-task.php. The manipulation of the argument task_...Show more
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file edit-task.php. The manipulation of the argument task_id leads to sql injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221452.Show less
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
1Craftercms
1Crafter Cms
Jun 17, 2026
Feb 17, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from...Show more
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26. Show less
1Hotels Server Project
1Hotels Server
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.
1Exponentcms
1Exponent Cms
Jun 17, 2026
Feb 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.
1Wow Company
1Wp Coder
Jun 17, 2026
Feb 17, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user suppl...Show more
The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrative privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.Show less
1Ecisp
1Espcms
Jun 17, 2026
Feb 17, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.
1Online Doctor Appointment Booking System Php And Mysql Project
1Online Doctor Appointment Booking System Php And Mysql
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.
1Simple Task Managing System Project
1Simple Task Managing System
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.
1Intern Record System Project
1Intern Record System
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.
1Online Pizza Ordering System Project
1Online Pizza Ordering System
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-opos/index.php. The manipulation of the argument ID l...Show more
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-opos/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221350 is the identifier assigned to this vulnerability.Show less
1Luckyframe
1Luckyframeweb
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.
1Luckyframe
1Luckyframeweb
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.
1Luckyframe
1Luckyframeweb
Jun 17, 2026
Feb 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.
1Ehoney Project
1Ehoney
Jun 17, 2026
Feb 15, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to execute arbitrary code.
1Rttys Project
1Rttys
Jun 17, 2026
Feb 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection vulnerability in rttys versions 4.0.0, 4.0.1, 4.0.2, and 4.4.x in api.go, allows attackers to execute arbitrary code.
1Dataease
1Dataease
Jun 17, 2026
Feb 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
1Seopanel
1Seo Panel
Jun 17, 2026
Feb 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.
1Cms Corephp Project
1Cms Corephp
Jun 17, 2026
Feb 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login.
1Uqcms
1Uqcms
Jun 17, 2026
Feb 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.