CWE-89
20,873 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,873)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php. |
In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL injection. This may result in loss of confidentiality, loss of integrity and DoS. |
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the...Show more |
1Liferay 3Digital Experience Platform DxpLiferay PortalJul 9, 2026 Nov 15, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticate...Show more |
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a Portle...Show more |
WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients. |
WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs. |
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/index.php?module=logs/view&type=php. |
1Zohocorp 3Manageengine Access Manager Plus Manageengine Pam360Manageengine Password Manager ProJun 17, 2026 Nov 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671. |
1Zohocorp 3Manageengine Access Manager Plus Manageengine Pam360Manageengine Password Manager ProJun 17, 2026 Nov 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection. |
A vulnerability classified as critical has been found in tsruban HHIMS 2.1. Affected is an unknown function of the component Patient Portrait Handler. The manipulation of the argument PID leads to sql injection. It is po...Show more |
A vulnerability was found in tholum crm42. It has been rated as critical. This issue affects some unknown processing of the file crm42\class\class.user.php of the component Login. The manipulation of the argument user_na...Show more |
A vulnerability classified as critical was found in eolinker goku_lite. This vulnerability affects unknown code of the file /plugin/getList. The manipulation of the argument route/keyword leads to sql injection. The atta...Show more |
A vulnerability classified as critical has been found in eolinker goku_lite. This affects an unknown part of the file /balance/service/list. The manipulation of the argument route/keyword leads to sql injection. It is po...Show more |
Arches is a web platform for creating, managing, & visualizing geospatial data. Versions prior to 6.1.2, 6.2.1, and 7.1.2 are vulnerable to SQL Injection. With a carefully crafted web request, it's possible to execute ce...Show more |
1Lineagrafica 1Eu Cookie Law Gdpr Jun 17, 2026 Nov 10, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ). |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Nov 9, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the categoriesId parameter at /php_action/fetchSelectedCategories.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Nov 9, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editfood.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Nov 9, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editclient.php. |