CWE-89
20,865 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,865)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Tours And Travels Management System Project 1Online Tours And Travels Management System Jun 17, 2026 Sep 23, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php. |
1Online Tours And Travels Management System Project 1Online Tours And Travels Management System Jun 17, 2026 Sep 23, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php. |
1Online Tours And Travels Management System Project 1Online Tours And Travels Management System Jun 17, 2026 Sep 23, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php. |
1Online Pet Shop Web Application Project 1Online Pet Shop Web Application Jun 17, 2026 Sep 22, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id. |
1Online Pet Shop Web Application Project 1Online Pet Shop Web Application Jun 17, 2026 Sep 22, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id |
1Online Pet Shop Web Application Project 1Online Pet Shop Web Application Jun 17, 2026 Sep 22, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id. |
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php. |
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=. |
1Simple Task Managing System Project 1Simple Task Managing System Jul 9, 2026 Sep 21, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php. |
1Simple Task Managing System Project 1Simple Task Managing System Jun 17, 2026 Sep 21, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at board.php. |
1Parantezteknoloji 1Koha Library Automation Jun 17, 2026 Sep 21, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01. |
1Databank 1Accreditation Tracking/presentation Module Jun 17, 2026 Sep 21, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2. |
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf. |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker c...Show more |
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. |
Final CMS 5.1.0 is vulnerable to SQL Injection. |