← Back
CWE-89

20,874 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,874)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rockoa
1Xinhu
Jun 17, 2026
Dec 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL Injection exits in xinhu < 2.5.0
1Laravel Jqgrid Project
1Laravel Jqgrid
Jun 17, 2026
Dec 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipula...Show more
A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is fbc2d94f43d0dc772767a5bdb2681133036f935e. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216271.Show less
1Pacman Canvas Project
1Pacman Canvas
Jun 17, 2026
Dec 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical has been found in pacman-canvas up to 1.0.5. Affected is the function addHighscore of the file data/db-handler.php. The manipulation leads to sql injection. It is possible to launch...Show more
A vulnerability classified as critical has been found in pacman-canvas up to 1.0.5. Affected is the function addHighscore of the file data/db-handler.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 1.0.6 is able to address this issue. The name of the patch is 29522c90ca1cebfce6453a5af5a45281d99b0646. It is recommended to upgrade the affected component. VDB-216270 is the identifier assigned to this vulnerability.Show less
1Otrs
1Otrs
Jun 17, 2026
Dec 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8....Show more
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.Show less
1Knexjs
1Knex
Nov 21, 2024
Dec 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.
1Crmx Project
1Crmx
Jun 17, 2026
Dec 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in luckyshot CRMx and classified as critical. This issue affects the function get/save/delete/comment/commentdelete of the file index.php. The manipulation leads to sql injection. The attack may...Show more
A vulnerability was found in luckyshot CRMx and classified as critical. This issue affects the function get/save/delete/comment/commentdelete of the file index.php. The manipulation leads to sql injection. The attack may be initiated remotely. The name of the patch is 8c62d274986137d6a1d06958a6f75c3553f45f8f. It is recommended to apply a patch to fix this issue. The identifier VDB-216185 was assigned to this vulnerability.Show less
1Roxlukas
1Lmeve
Jun 17, 2026
Dec 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in roxlukas LMeve and classified as critical. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument X-Forwarded-For leads to sql inje...Show more
A vulnerability was found in roxlukas LMeve and classified as critical. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument X-Forwarded-For leads to sql injection. The attack may be launched remotely. The name of the patch is 29e1ead3bb1c1fad53b77dfc14534496421c5b5d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216176.Show less
1Online Grading System Project
1Online Grading System
Jun 17, 2026
Dec 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter.
1Ruoyi
1Ruoyi
Jun 17, 2026
Dec 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file com/ruoyi/generator/controller/GenController. The manipulation leads to s...Show more
A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file com/ruoyi/generator/controller/GenController. The manipulation leads to sql injection. The name of the patch is 167970e5c4da7bb46217f576dc50622b83f32b40. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215975.Show less
1Google
1Android
Jun 17, 2026
Dec 16, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not need...Show more
In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770183Show less
1Google
1Android
Jun 17, 2026
Dec 16, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed...Show more
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203Show less
1Google
1Android
Jun 17, 2026
Dec 16, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. Us...Show more
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224769956Show less
1Blocksera
1Cryptocurrency Widgets Pack
Jun 17, 2026
Dec 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
1Logrocket Oauth2 Example Project
1Logrocket Oauth2 Example
Jun 17, 2026
Dec 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
1Bangresto Project
1Bangresto
Jun 17, 2026
Dec 14, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.
1Helmet Store Showroom Project
1Helmet Store Showroom
Jun 17, 2026
Dec 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/classes/Master.php?f=delete_product.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/brands/manage_brand.php?id=.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=client/manage_client&id=.