CWE-89
20,873 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,873)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter. |
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter. |
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using...Show more |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 2, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 2, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Master.php?f=delete_message. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 2, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/admin/?page=appointments/view_appointment. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 2, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment. |
1Garage Management System Project 1Garage Management System Jun 17, 2026 Nov 2, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php. |
1Slims 1Senayan Library Management System Jun 17, 2026 Nov 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Nov 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Nov 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Nov 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Nov 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php. |
1Ndk Design 1Ndkadvancedcustomizationfields Jul 9, 2026 Nov 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data. |
A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The att...Show more |
A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /api/v2/open/rowsInfo. The manipulation of the argument order leads to sql injection. It is possible...Show more |
A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads...Show more |
A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be...Show more |
A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack rem...Show more |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php. |