← Back
CWE-89

20,874 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,874)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=user/manage_user&id=.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/view_category.php?id=.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/manage_product&id=.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/view_product&id=.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=categories&c=.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=product_per_brand&bid=.
1Helmet Store Showroom Site Project
1Helmet Store Showroom Site
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=.
1M0ver
1Bible Online
Jun 17, 2026
Dec 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the function query of the file src/main/java/custom/application/search.java of the component Search Handl...Show more
A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the function query of the file src/main/java/custom/application/search.java of the component Search Handler. The manipulation leads to sql injection. The name of the patch is 6ef0aabfb2d4ccd53fcaa9707781303af357410e. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215444.Show less
1Aerocms Project
1Aerocms
Jun 17, 2026
Dec 13, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.
1Aerocms Project
1Aerocms
Jun 17, 2026
Dec 13, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.
1Sap
1Netweaver Process Integration
Jun 17, 2026
Dec 13, 2022
N/A· v4
8.6 HIGH· v3
N/A· v2
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming a...Show more
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data across the entire system. This allows the attacker to have full read access to user data, make limited modifications to user data, and degrade the performance of the system, leading to a high impact on confidentiality and a limited impact on the availability and integrity of the application. Show less
1Sap
1Netweaver Process Integration
Jun 17, 2026
Dec 13, 2022
N/A· v4
9.4 CRITICAL· v3
N/A· v2
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to...Show more
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized operations. The vulnerability affects local users and data, leading to a considerable impact on confidentiality as well as availability and a limited impact on the integrity of the application. These operations can be used to: * Read any information * Modify sensitive information * Denial of Service attacks (DoS) * SQL Injection Show less
2Dokan
Wedevs
2Dokan
Dokan
Jun 17, 2026
Dec 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
1Mxsdoc Project
1Mxsdoc
Jun 17, 2026
Dec 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability was found in RainyGao DocSys. It has been declared as critical. This vulnerability affects the function getReposAllUsers of the file /DocSystem/Repos/getReposAllUsers.do. The manipulation of the argument...Show more
A vulnerability was found in RainyGao DocSys. It has been declared as critical. This vulnerability affects the function getReposAllUsers of the file /DocSystem/Repos/getReposAllUsers.do. The manipulation of the argument searchWord/reposId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-215278 is the identifier assigned to this vulnerability.Show less
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Dec 11, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability classified as critical was found in SourceCodester Canteen Management System. This vulnerability affects unknown code of the file ajax_represent.php. The manipulation of the argument customer_id leads to...Show more
A vulnerability classified as critical was found in SourceCodester Canteen Management System. This vulnerability affects unknown code of the file ajax_represent.php. The manipulation of the argument customer_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215272.Show less
1Nodau Project
1Nodau
Jun 17, 2026
Dec 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/db.c. The manipulation of the argument value/name leads to sql inje...Show more
A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/db.c. The manipulation of the argument value/name leads to sql injection. The name of the patch is 7a7d737a3929f335b9717ddbd31db91151b69ad2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215252.Show less
1Cube
1Cube.js
Jun 17, 2026
Dec 9, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This iss...Show more
cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised to either upgrade to 0.31.24 or to downgrade to 0.31.22. There are no known workarounds for this vulnerability.Show less
1Interspire
1Email Marketer
Jun 17, 2026
Dec 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the...Show more
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.Show less
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Dec 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.