CWE-89
20,874 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,874)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Automotive Shop Management System Project 1Automotive Shop Management System Jun 17, 2026 Nov 25, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/admin/products/manage_product.php. |
1Automotive Shop Management System Project 1Automotive Shop Management System Jun 17, 2026 Nov 25, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php. |
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin. |
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin. |
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString. |
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check. |
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. |
1Stock Management System Project 1Stock Management System Jun 17, 2026 Nov 24, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/pass...Show more |
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component. |
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. |
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL. |
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component. |
SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1. |
1Sanitization Management System Project 1Sanitization Management System Jun 17, 2026 Nov 23, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=. |
1Apartment Visitors Management System Project 1Apartment Visitors Management System Jun 17, 2026 Nov 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php. |
1Billing System Project Project 1Billing System Project Jun 17, 2026 Nov 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. |
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases. |
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information. |
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information. |
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information. |