← Back
CWE-89

20,873 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,873)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aerocms Project
1Aerocms
Jun 17, 2026
Nov 22, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
1Billing System Project Project Project
1Billing System Project
Jun 17, 2026
Nov 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.
1Zte
1Mf286r Firmware
Jun 17, 2026
Nov 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL inje...Show more
There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.Show less
1Klik Socialmediawebsite Project
1Klik Socialmediawebsite
Jun 17, 2026
Nov 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
1Billing System Project
1Billing System
Jun 17, 2026
Nov 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.
1Billing System Project
1Billing System
Jun 17, 2026
Nov 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.
1Mybb
1Mybb
Jun 17, 2026
Nov 22, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.
1Maggioli
1Appalti & Contratti
Jun 17, 2026
Nov 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the Get...Show more
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.Show less
1Silverstripe
1Framework
Jun 17, 2026
Nov 21, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Nov 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL...Show more
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affectedShow less
1Api2cart
1Api2cart Bridge Connector
Jun 17, 2026
Nov 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=transactions/manage_transaction&id=.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/view_mechanic.php?id=.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/services/manage_service.php?id=.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/manage_mechanic.php?id=.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_service.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
Nov 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.
1Deltaww
1Diaenergie
Jun 17, 2026
Nov 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
1Deltaww
1Diaenergie
Jun 17, 2026
Nov 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
1Deltaww
1Diaenergie
Jun 17, 2026
Nov 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network