← Back
CWE-89

20,864 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,864)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Sep 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection
1Church Management System Project
1Church Management System
Jun 17, 2026
Sep 15, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php.
1Church Management System Project
1Church Management System
Jun 17, 2026
Sep 15, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php.
1Glpi Project
1Glpi
Jun 17, 2026
Sep 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions have be...Show more
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions have been found to be vulnerable to a SQL injection attack which an attacker could leverage to simulate an arbitrary user login. Users are advised to upgrade to version 10.0.3. Users unable to upgrade should disable the `Enable login with external token` API configuration.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Sep 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In affected versions requ...Show more
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In affected versions request input is not properly validated in the plugin controller and can be used to access low-level API of Plugin class. An attacker can, for instance, alter database data. Attacker must have "General setup" update rights to be able to perform this attack. Users are advised to upgrade to version 10.0.3. Users unable to upgrade should remove the `front/plugin.form.php` script.Show less
1Razormist
1Loan Management System
Jun 17, 2026
Sep 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.
1Hospital Information System Project
1Hospital Information System
Jun 17, 2026
Sep 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
1Transtek
1Mojodat Fixed Asset Management
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify qu...Show more
In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database.Show less
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.
1Microsoft
1Dynamics 365
Jun 17, 2026
Sep 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
1Archerydms
1Archery
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above.
1Archerydms
1Archery
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.
1Archerydms
1Archery
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.
1Archerydms
1Archery
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply.
1Archerydms
1Archery
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module.
1Archerydms
1Archery
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface.
1Bpcbt
1Smartvista Front End
Jul 9, 2026
Sep 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.
1Online Leave Management System Project
1Online Leave Management System
Jun 17, 2026
Sep 12, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php.
1Online Leave Management System Project
1Online Leave Management System
Jun 17, 2026
Sep 12, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /employees/manage_leave_type.php.