← Back
CWE-89

20,874 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,874)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 25, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/admin/products/manage_product.php.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 25, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.
1Jeecg
1Jeecg Boot
Jul 9, 2026
Nov 25, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
1Jeecg
1Jeecg Boot
Jul 9, 2026
Nov 25, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
1Jeecg
1Jeecg Boot
Jul 9, 2026
Nov 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
1Jeecg
1Jeecg Boot
Jul 9, 2026
Nov 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
1Jeecg
1Jeecg Boot
Jul 9, 2026
Nov 25, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
1Stock Management System Project
1Stock Management System
Jun 17, 2026
Nov 24, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/pass...Show more
A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214322 is the identifier assigned to this vulnerability.Show less
1Jizhicms
1Jizhicms
Jun 17, 2026
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.
1Dedebiz
1Dedecmsv6
Jun 17, 2026
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
1Boa
1Boa
Jun 17, 2026
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.
1Jizhicms
1Jizhicms
Jun 17, 2026
Nov 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
1Cms Php Project
1Cms Php
Jun 17, 2026
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Nov 23, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.
1Apartment Visitors Management System Project
1Apartment Visitors Management System
Jun 17, 2026
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.
1Billing System Project Project
1Billing System Project
Jun 17, 2026
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.
1Maarch
1Maarch Rm
Jul 9, 2026
Nov 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.
1Aerocms Project
1Aerocms
Jun 17, 2026
Nov 22, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.
1Aerocms Project
1Aerocms
Jun 17, 2026
Nov 22, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
1Aerocms Project
1Aerocms
Jun 17, 2026
Nov 22, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.