← Back
CWE-89

20,873 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,873)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mkcms Project
1Mkcms
Jun 17, 2026
Nov 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
1Mkcms Project
1Mkcms
Jun 17, 2026
Nov 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
1Glpi Project
1Glpi
Jun 17, 2026
Nov 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using...Show more
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been patched, please upgrade to version 10.0.4. As a workaround, disable login with user_token on API Rest.Show less
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 2, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 2, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Master.php?f=delete_message.
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 2, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/admin/?page=appointments/view_appointment.
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 2, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Nov 2, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.
1Slims
1Senayan Library Management System
Jun 17, 2026
Nov 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
1Ndk Design
1Ndkadvancedcustomizationfields
Jul 9, 2026
Nov 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data.
1Ibax
1Go Ibax
Jun 17, 2026
Nov 1, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The att...Show more
A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212638 is the identifier assigned to this vulnerability.Show less
1Ibax
1Go Ibax
Jun 17, 2026
Nov 1, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /api/v2/open/rowsInfo. The manipulation of the argument order leads to sql injection. It is possible...Show more
A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /api/v2/open/rowsInfo. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212637 was assigned to this vulnerability.Show less
1Ibax
1Go Ibax
Jun 17, 2026
Nov 1, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads...Show more
A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212636.Show less
1Ibax
1Go Ibax
Jun 17, 2026
Nov 1, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be...Show more
A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212635.Show less
1Ibax
1Go Ibax
Jun 17, 2026
Nov 1, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack rem...Show more
A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212634 is the identifier assigned to this vulnerability.Show less
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Nov 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.