CWE-89
20,865 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,865)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Simple Cold Storage Management System Project 1Simple Cold Storage Managment System Jun 17, 2026 Oct 11, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=. |
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Oct 7, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Oct 7, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=. |
1Online Pet Shop We App Project 1Online Pet Shop We App Jun 17, 2026 Oct 7, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=inventory/manage_inventory. |
1Online Pet Shop We App Project 1Online Pet Shop We App Jun 17, 2026 Oct 7, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=maintenance/manage_category. |
1Open Source Sacco Management System Project 1Open Source Sacco Management System Jun 17, 2026 Oct 7, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_payment. |
1Open Source Sacco Management System Project 1Open Source Sacco Management System Jun 17, 2026 Oct 7, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_loan. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Oct 7, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /diagnostic/edittest.php. |
1Simple E Learning System Project 1Simple E Learning System Jun 17, 2026 Oct 7, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode. |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not a valid vulnerabili...Show more |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerabili...Show more |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerabil...Show more |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnera...Show more |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have disputed this as not a valid vulnerability...Show more |