CWE-89
20,874 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,874)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA. |
SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/contro...Show more |
1Sanitization Management System Project 1Sanitization Management System Jun 17, 2026 Nov 30, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=. |
1Sanitization Management System Project 1Sanitization Management System Jun 17, 2026 Nov 30, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=. |
1Sanitization Management System Project 1Sanitization Management System Jun 17, 2026 Nov 30, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=. |
1Sanitization Management System Project 1Sanitization Management System Jun 17, 2026 Nov 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Nov 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects the function query of the file ajax_invoice.php of the component POST Request Handler. The manipula...Show more |
1Church Management System Project 1Church Management System Jun 17, 2026 Nov 30, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php. |
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. |
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information. |
1Online Shopping System Advanced Project 1Online Shopping System Advanced Jun 17, 2026 Nov 29, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php. |
1Poultry Farm Management System Project 1Poultry Farm Management System Jun 17, 2026 Nov 28, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php. |
1Wp User Merger Project 1Wp User Merger Jun 17, 2026 Nov 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin |
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author |
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users |
1Lahirudanushka 1School Management System Jun 17, 2026 Nov 28, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries. |
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface...Show more |
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface...Show more |
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/do...Show more |
1Automotive Shop Management System Project 1Automotive Shop Management System Jun 17, 2026 Nov 25, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/transactions/update_status.php. |