← Back
CWE-89

20,860 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,860)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Owasp
2Debian Linux
Owasp Modsecurity Core Rule Set
Jun 17, 2026
Sep 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF prot...Show more
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.Show less
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Sep 2, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
1Oretnom23
1Clinic's Patient Management System
Jun 17, 2026
Sep 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.
1Mybatis
1Mapper
Jun 17, 2026
Sep 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.
2Online Food Ordering System Project
Oretnom23
2Online Food Ordering System
Online Food Ordering System
Jun 17, 2026
Sep 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.
1Redhat
1Advanced Cluster Management For Kubernetes
Jun 17, 2026
Sep 1, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific str...Show more
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.Show less
1Simple Task Scheduling System Project
1Simple Task Scheduling System
Jun 17, 2026
Sep 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php.
1Simple Task Scheduling System Project
1Simple Task Scheduling System
Jun 17, 2026
Sep 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/manage_schedule.php.
1Simple Task Scheduling System Project
1Simple Task Scheduling System
Jun 17, 2026
Sep 1, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/view_schedule.php.
1Doctor's Appointment System Project
1Doctor's Appointment System
Jun 17, 2026
Aug 31, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.
1Online Ordering System Project
1Online Ordering System
Jun 17, 2026
Aug 31, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
1Aerocms Project
1Aerocms
Jun 17, 2026
Aug 31, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
1Postgresql
1Postgresql
Jun 17, 2026
Aug 31, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW,...Show more
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.Show less
1Library Management System Project
1Library Management System
Jun 17, 2026
Aug 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php.
1Library Management System Project
1Library Management System
Jun 17, 2026
Aug 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admin/delstu.php.
1Library Management System Project
1Library Management System
Jun 17, 2026
Aug 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php.
1Library Management System Project
1Library Management System
Jun 17, 2026
Aug 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /librarian/dele.php.
1Library Management System Project
1Library Management System
Jun 17, 2026
Aug 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php.
1Library Management System Project
1Library Management System
Jun 17, 2026
Aug 30, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /librarian/delete.php.
1Hgiga
1Oaklouds Portal
Jun 17, 2026
Aug 30, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and...Show more
OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service.Show less