CWE-89
20,865 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,865)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wedding Planner Project 1Wedding Planner Jun 17, 2026 Sep 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php. |
1Wedding Planner Project 1Wedding Planner Jun 17, 2026 Sep 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php. |
1Wedding Planner Project 1Wedding Planner Jun 17, 2026 Sep 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php. |
1Online Leave Management System Project 1Online Leave Management System Jun 17, 2026 Sep 26, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_application. |
1Online Leave Management System Project 1Online Leave Management System Jun 17, 2026 Sep 26, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designation. |
1Online Leave Management System Project 1Online Leave Management System Jun 17, 2026 Sep 26, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_type. |
1Wedding Planner Project 1Wedding Planner Jun 17, 2026 Sep 26, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php. |
1Wedding Planner Project 1Wedding Planner Jun 17, 2026 Sep 26, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php. |
1Wedding Planner Project 1Wedding Planner Jun 17, 2026 Sep 26, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Sep 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds.php. |
A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password token through or a 2fa secret. |