← Back
CWE-89

20,865 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,865)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Tours And Travels Management System Project
1Online Tours And Travels Management System
Jun 17, 2026
Sep 23, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.
1Online Tours And Travels Management System Project
1Online Tours And Travels Management System
Jun 17, 2026
Sep 23, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php.
1Online Tours And Travels Management System Project
1Online Tours And Travels Management System
Jun 17, 2026
Sep 23, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php.
1Online Pet Shop Web Application Project
1Online Pet Shop Web Application
Jun 17, 2026
Sep 22, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.
1Online Pet Shop Web Application Project
1Online Pet Shop Web Application
Jun 17, 2026
Sep 22, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id
1Online Pet Shop Web Application Project
1Online Pet Shop Web Application
Jun 17, 2026
Sep 22, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.
1Zzcms
1Zzcms
Jun 17, 2026
Sep 22, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
1Zzcms
1Zzcms
Jun 17, 2026
Sep 22, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.
1Simple Task Managing System Project
1Simple Task Managing System
Jul 9, 2026
Sep 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
1Simple Task Managing System Project
1Simple Task Managing System
Jun 17, 2026
Sep 21, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at board.php.
1Parantezteknoloji
1Koha Library Automation
Jun 17, 2026
Sep 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.
1Databank
1Accreditation Tracking/presentation Module
Jun 17, 2026
Sep 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.
1Bpcbt
1Smartvista Front End
Jul 9, 2026
Sep 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Sep 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Sep 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Sep 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Sep 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Sep 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.Show less
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Sep 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Sep 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Final CMS 5.1.0 is vulnerable to SQL Injection.