← Back
CWE-89

20,873 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,873)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editcategory.php.
1Sap
1Sql Anywhere
Jun 17, 2026
Nov 8, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor.
1Zte
1Zaip Aie
Jun 17, 2026
Nov 8, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attack by building malicious requests. Exploitation of this vulnerability could cause...Show more
There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attack by building malicious requests. Exploitation of this vulnerability could cause the leakage of the current table content.Show less
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 7, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youthappam/add-food.php.
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 7, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete.
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 7, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test.
1Oretnom23
1Food Ordering Management System
Jun 17, 2026
Nov 7, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all-orders.php?status=Cancelled%20by%20Customer.
1Maxonerp
1Maxon
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is...Show more
A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213039.Show less
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Nov 7, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote.
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Nov 7, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_inquiry.
1Oretnom23
1Human Resource Management System
Jun 17, 2026
Nov 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the stateedit parameter at /hrm/state.php.
1Really Simple Plugins
1Complianz
Jun 17, 2026
Nov 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected tra...Show more
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.Show less
1Opmc
1Woocommerce Dropshipping
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injec...Show more
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injectionShow less
1Cisco
1Asyncos
Jun 17, 2026
Nov 4, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on...Show more
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database of the affected system. Show less
1Schneider Electric
2Ecostruxure Operator Terminal Expert
Pro Face Blue
Jun 17, 2026
Nov 4, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of pr...Show more
A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).Show less
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 3, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 3, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_appointment.
1Auieo
1Candidats
Jun 17, 2026
Nov 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi...Show more
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.Show less
1Opencart
1Opencart
Jun 17, 2026
Nov 3, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.
1Mkcms Project
1Mkcms
Jun 17, 2026
Nov 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.