CWE-89
20,860 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,860)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Gym Management System Project 1Gym Management System Jun 17, 2026 Aug 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument user_email leads to sql injection. It is...Show more |
1Deliciousbrains 1Better Search Replace Jun 17, 2026 Aug 22, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before inserting it into a SQL query, which could allow high privilege users to perform SQL Injection attacks |
1Transposh 1Transposh Wordpress Translation Jun 17, 2026 Aug 22, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby parameters before using them in a SQL statement, leading to a SQL injection |
1Phpgurukul 1Bus Pass Management System Jun 17, 2026 Aug 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php,...Show more |
1Project Nexus Project 1Project Nexus Jun 17, 2026 Aug 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict u...Show more |
jizhicms v2.3.1 has SQL injection in the background. |
Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database. |
Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librarian/del.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staff/delete.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /student/dele.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php. |
CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candidateID', in '/index.php?m=jo...Show more |
1Barangay Management System Project 1Barangay Management System Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php. |
1Student Management System Project 1Student Management System Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability, which was classified as critical, was found in SourceCodester Student Management System. Affected is an unknown function of the file index.php. The manipulation of the argument id leads to sql injection....Show more |
Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter. |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.' |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc. |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt. |