CWE-89
20,868 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,868)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php. |
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php. |
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php. |
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php. |
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php. |
1Phpgurukul 1Employee Record Management System Jun 17, 2026 Oct 28, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Oct 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php. |
1Canteen Management System Project 1Canteen Management System Jun 17, 2026 Oct 28, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php. |
A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functionality of the file /api/v1/bait/set. The manipulation of the argument Payload leads to sql injection....Show more |
A vulnerability, which was classified as critical, has been found in seccome Ehoney. This issue affects some unknown processing of the file /api/v1/attack. The manipulation of the argument AttackIP leads to sql injection...Show more |
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIACloud. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL quer...Show more |
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issu...Show more |
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary...Show more |
1School Activity Updates With Sms Notification Project 1School Activity Updates With Sms Notification Jun 17, 2026 Oct 27, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=. |
1Oretnom23 1Online Medicine Ordering System Jun 17, 2026 Oct 27, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id...Show more |
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system. |
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list |
1Elearning System Project 1Elearning System Jun 17, 2026 Oct 26, 2022 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in SourceCodester eLearning System 1.0. This vulnerability affects unknown code of the file /admin/students/manage.php. The manipulation of the argument id leads to sql in...Show more |
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used. |