← Back
CWE-89

20,876 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,876)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tuzicms Project
1Tuzicms
Jun 17, 2026
Jan 12, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability classified as critical has been found in TuziCMS 2.0.6. This affects the function index of the file App\Manage\Controller\ArticleController.class.php of the component Article Module. The manipulation of t...Show more
A vulnerability classified as critical has been found in TuziCMS 2.0.6. This affects the function index of the file App\Manage\Controller\ArticleController.class.php of the component Article Module. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-218151.Show less
1Domino Project
1Domino
Nov 21, 2024
Jan 11, 2023
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
A vulnerability was found in dobos domino. It has been rated as critical. Affected by this issue is some unknown functionality in the library src/Complex.Domino.Lib/Lib/EntityFactory.cs. The manipulation leads to sql inj...Show more
A vulnerability was found in dobos domino. It has been rated as critical. Affected by this issue is some unknown functionality in the library src/Complex.Domino.Lib/Lib/EntityFactory.cs. The manipulation leads to sql injection. Upgrading to version 0.1.5524.38553 is able to address this issue. The name of the patch is 16f039073709a21a76526110d773a6cce0ce753a. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218024.Show less
1Pplv2 Project
1Pplv2
Nov 21, 2024
Jan 11, 2023
N/A· v4
8.0 HIGH· v3
5.2 MEDIUM· v2
A vulnerability was found in nym3r0s pplv2. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The patch is named 28f8b0550104044da09f04...Show more
A vulnerability was found in nym3r0s pplv2. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The patch is named 28f8b0550104044da09f04659797487c59f85b00. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218023.Show less
1Criminals Project
1Criminals
Nov 21, 2024
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability was found in NoxxieNl Criminals. It has been classified as critical. Affected is an unknown function of the file ingame/roulette.php. The manipulation of the argument gambleMoney leads to sql injection. T...Show more
A vulnerability was found in NoxxieNl Criminals. It has been classified as critical. Affected is an unknown function of the file ingame/roulette.php. The manipulation of the argument gambleMoney leads to sql injection. The patch is identified as 0a60b31271d4cbf8babe4be993d2a3a1617f0897. It is recommended to apply a patch to fix this issue. VDB-218022 is the identifier assigned to this vulnerability.Show less
1Gmail Servlet Project
1Gmail Servlet
Nov 21, 2024
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability was found in gmail-servlet and classified as critical. This issue affects the function search of the file src/Model.java. The manipulation leads to sql injection. The identifier of the patch is 5d72753c2e...Show more
A vulnerability was found in gmail-servlet and classified as critical. This issue affects the function search of the file src/Model.java. The manipulation leads to sql injection. The identifier of the patch is 5d72753c2e95bb373aa86824939397dc25f679ea. It is recommended to apply a patch to fix this issue. The identifier VDB-218021 was assigned to this vulnerability.Show less
1Ibm
1Sterling Partner Engagement Manager
Jun 17, 2026
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete in...Show more
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208. Show less
1Lead Management System Project
1Lead Management System
Jun 17, 2026
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
1Lead Management System Project
1Lead Management System
Jun 17, 2026
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
1Lead Management System Project
1Lead Management System
Jun 17, 2026
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
1Lead Management System Project
1Lead Management System
Jun 17, 2026
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.
1Lead Management System Project
1Lead Management System
Jun 17, 2026
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
1Piwallet Project
1Piwallet
Nov 21, 2024
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability was found in jfm-so piWallet. It has been rated as critical. Affected by this issue is some unknown functionality of the file api.php. The manipulation of the argument key leads to sql injection. The patc...Show more
A vulnerability was found in jfm-so piWallet. It has been rated as critical. Affected by this issue is some unknown functionality of the file api.php. The manipulation of the argument key leads to sql injection. The patch is identified as b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb. It is recommended to apply a patch to fix this issue. VDB-218006 is the identifier assigned to this vulnerability.Show less
1Voyager Project
1Voyager
Nov 21, 2024
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability was found in Nayshlok Voyager. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file Voyager/src/models/DatabaseAccess.java. The manipulation leads to sq...Show more
A vulnerability was found in Nayshlok Voyager. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file Voyager/src/models/DatabaseAccess.java. The manipulation leads to sql injection. The identifier of the patch is f1249f438cd8c39e7ef2f6c8f2ab76b239a02fae. It is recommended to apply a patch to fix this issue. The identifier VDB-218005 was assigned to this vulnerability.Show less
1Lead Management System Project
1Lead Management System
Jun 17, 2026
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.
1Lead Management System Project
1Lead Management System
Jun 17, 2026
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.
1Aci Escola Project
1Aci Escola
Nov 21, 2024
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability, which was classified as critical, was found in ACI_Escola. This affects an unknown part. The manipulation leads to sql injection. The identifier of the patch is 34eed1f7b9295d1424912f79989d8aba5de41e9f....Show more
A vulnerability, which was classified as critical, was found in ACI_Escola. This affects an unknown part. The manipulation leads to sql injection. The identifier of the patch is 34eed1f7b9295d1424912f79989d8aba5de41e9f. It is recommended to apply a patch to fix this issue. The identifier VDB-217965 was assigned to this vulnerability.Show less
1Dronfelipe Project
1Dronfelipe
Nov 21, 2024
Jan 11, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability was found in kylebebak dronfelipe. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The patch is named 87405b74fe65189...Show more
A vulnerability was found in kylebebak dronfelipe. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The patch is named 87405b74fe651892d79d0dff62ed17a7eaef6a60. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217951.Show less
1Webchess Project
1Webchess
Jun 17, 2026
Jan 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).
1Opensuse
1Travel Support Program
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Hash) can be extracted via Ransack query injection. Every deployment of t...Show more
Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Hash) can be extracted via Ransack query injection. Every deployment of travel-support-program below the patched version is affected. The travel-support-program uses the Ransack library to implement search functionality. In its default configuration, Ransack will allow for query conditions based on properties of associated database objects [1]. The `*_start`, `*_end` or `*_cont` search matchers [2] can then be abused to exfiltrate sensitive string values of associated database objects via character-by-character brute-force (A match is indicated by the returned JSON not being empty). A single bank account number can be extracted with <200 requests, a password hash can be extracted with ~1200 requests, all within a few minutes. The problem has been patched in commit d22916275c51500b4004933ff1b0a69bc807b2b7. In order to work around this issue, you can also cherry pick that patch, however it will not work without the Rails 5.0 migration that was done in #150, which in turn had quite a few pull requests it depended on.Show less
1Archibus
1Web Central
Jun 17, 2026
Jan 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL inje...Show more
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL injection.Show less