CWE-89
20,864 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection |
1Church Management System Project 1Church Management System Jun 17, 2026 Sep 15, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php. |
1Church Management System Project 1Church Management System Jun 17, 2026 Sep 15, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php. |
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions have be...Show more |
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In affected versions requ...Show more |
1Razormist 1Loan Management System Jun 17, 2026 Sep 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form. |
1Hospital Information System Project 1Hospital Information System Jun 17, 2026 Sep 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. |
1Transtek 1Mojodat Fixed Asset Management Jun 17, 2026 Sep 13, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request. |
1Nokia 11350 Optical Management System Jun 17, 2026 Sep 13, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify qu...Show more |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Sep 13, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page. |
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability |
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above. |
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface. |
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface. |
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply. |
Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module. |
Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface. |
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf. |
1Online Leave Management System Project 1Online Leave Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php. |
1Online Leave Management System Project 1Online Leave Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /employees/manage_leave_type.php. |