← Back
CWE-89

20,874 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,874)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sophos
1Xg Firewall Firmware
Jun 17, 2026
Dec 1, 2022
N/A· v4
2.7 LOW· v3
N/A· v2
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
1Isic.lk Project
1Isic.lk
Jun 17, 2026
Dec 1, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/contro...Show more
SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.Show less
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Nov 30, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=.
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Nov 30, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=.
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Nov 30, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=.
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Nov 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects the function query of the file ajax_invoice.php of the component POST Request Handler. The manipula...Show more
A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects the function query of the file ajax_invoice.php of the component POST Request Handler. The manipulation of the argument search leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214523.Show less
1Church Management System Project
1Church Management System
Jun 17, 2026
Nov 30, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php.
1Owncast Project
1Owncast
Jun 17, 2026
Nov 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
1Aerocms Project
1Aerocms
Jun 17, 2026
Nov 29, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.
1Online Shopping System Advanced Project
1Online Shopping System Advanced
Jun 17, 2026
Nov 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
1Poultry Farm Management System Project
1Poultry Farm Management System
Jun 17, 2026
Nov 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.
1Wp User Merger Project
1Wp User Merger
Jun 17, 2026
Nov 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin
1Wpsmartcontracts
1Wpsmartcontracts
Jun 17, 2026
Nov 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
1Linksoftwarellc
1Html Forms
Jun 17, 2026
Nov 28, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
1Lahirudanushka
1School Management System
Jun 17, 2026
Nov 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
1Linuxfoundation
1Opendaylight
Jun 17, 2026
Nov 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface...Show more
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.Show less
1Linuxfoundation
1Opendaylight
Jun 17, 2026
Nov 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface...Show more
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface /auth/v1/users/ is used.Show less
1Linuxfoundation
1Opendaylight
Jun 17, 2026
Nov 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/do...Show more
A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/domains/ API interface.Show less
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 25, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/transactions/update_status.php.