CWE-89
20,865 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,865)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability. |
1Online Leave Management System Project 1Online Leave Management System Jun 17, 2026 Oct 6, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /leave_system/classes/Master.php?f=delete_department. |
1Oretnom23 1Simple Cold Storage Management System Jun 17, 2026 Oct 6, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=. |
1Oretnom23 1Simple Cold Storage Management System Jun 17, 2026 Oct 6, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=. |
1Oretnom23 1Simple Cold Storage Management System Jun 17, 2026 Oct 6, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id=. |
1Oretnom23 1Simple Cold Storage Management System Jun 17, 2026 Oct 6, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking. |
1Oretnom23 1Simple Cold Storage Management System Jun 17, 2026 Oct 6, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message. |
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting idm, nbars, and SLP manager code. |
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a second-order SQL Injection attack affecting the NBFSMCLIENT service by leveraging CV...Show more |
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service. |
1Phpgurukul 1Dairy Farm Shop Management System Jun 17, 2026 Sep 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file. |
1Phpgurukul 1Bus Pass Management System Jul 9, 2026 Sep 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php.. |
1Phpgurukul 1Dairy Farm Shop Management System Jun 17, 2026 Sep 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Sep 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A limited SQL injection risk was identified in the "browse list of users" site administration page. |
A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution. |
1Billing System Project Project 1Billing System Project Jun 17, 2026 Sep 30, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php. |
1Billing System Project Project 1Billing System Project Jun 17, 2026 Sep 30, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php. |
1Hospital Management System Mini Project Project 1Hospital Management System Mini Project Jun 17, 2026 Sep 29, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter. |
1Best Student Result Management System Project 1Best Student Result Management System Jun 17, 2026 Sep 29, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection. |