CWE-89
20,860 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,860)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ingredients Stock Management System Project 1Ingredients Stock Management System Jun 17, 2026 Aug 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /stocks/manage_stockin.php. |
1Ingredients Stock Management System Project 1Ingredients Stock Management System Jun 17, 2026 Aug 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/view_item.php. |
1Ingredients Stock Management System Project 1Ingredients Stock Management System Jun 17, 2026 Aug 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php. |
1Ingredients Stock Management System Project 1Ingredients Stock Management System Jun 17, 2026 Aug 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/manage_category.php. |
1Ingredients Stock Management System Project 1Ingredients Stock Management System Jun 17, 2026 Aug 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php. |
Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a...Show more |
1Simple And Nice Shopping Cart Script Project 1Simple And Nice Shopping Cart Script Jun 17, 2026 Aug 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of...Show more |
An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar. |
SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earl...Show more |
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php. |
Bluecms 1.6 has SQL injection in line 132 of admin/area.php |
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php |
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php |
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list. |
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request t...Show more |
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request t...Show more |
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request t...Show more |
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request t...Show more |