CWE-89
20,866 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,866)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Oretnom23 1Simple Cold Storage Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/classes/Master.php?f=delete_storage. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell. |
1Sanitization Management System Project 1Sanitization Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affects some unknown processing of the file /php-sms/?p=services/view_service. The manipulation of the arg...Show more |
1Simple Online Public Access Catalog Project 1Simple Online Public Access Catalog Jun 17, 2026 Oct 14, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. This vulnerability affects unknown code of the file /opac/Actions.php?a=login of the component Admin Lo...Show more |
1Open Source Sacco Management System Project 1Open Source Sacco Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php. |
1Open Source Sacco Management System Project 1Open Source Sacco Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php. |
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. |
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. |
Ree6 is a moderation bot. This vulnerability allows manipulation of SQL queries. This issue has been patched in version 1.7.0 by using Javas PreparedStatements, which allow object setting without the risk of SQL injectio...Show more |
1Resiot 1Iot Platform And Lorawan Network Server Jun 17, 2026 Oct 13, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST request to /ResiotQueryDBActive. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 13, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability classified as critical has been found in SourceCodester Human Resource Management System. This affects an unknown part of the file getstatecity.php. The manipulation of the argument ci leads to sql inject...Show more |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 13, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file city.php. The manipulation of the argument cit...Show more |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 13, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file city.php. The manipulation of the arg...Show more |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 13, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Human Resource Management System. It has been classified as critical. Affected is an unknown function of the file getstatecity.php. The manipulation of the argument sc leads to...Show more |
1Newsletter Subscribe (popup + Regular Module) Project 1Newsletter Subscribe (popup + Regular Module) Jun 17, 2026 Oct 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter. |
1Open Source Sacco Management System Project 1Open Source Sacco Management System Jun 17, 2026 Oct 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan. |
1Open Source Sacco Management System Project 1Open Source Sacco Management System Jun 17, 2026 Oct 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower. |
1Online Pet Shop We App Project 1Online Pet Shop We App Jun 17, 2026 Oct 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order. |
1Online Pet Shop We App Project 1Online Pet Shop We App Jun 17, 2026 Oct 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order. |