← Back
CWE-89

20,860 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,860)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Inventorymanagementsystem Project
1Inventorymanagementsystem
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user.
1Inventorymanagementsystem Project
1Inventorymanagementsystem
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
1Inventorymanagementsystem Project
1Inventorymanagementsystem
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode.
1Inventorymanagementsystem Project
1Inventorymanagementsystem
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username.
1Maccms
1Maccms
Jun 17, 2026
Aug 17, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
1Xxyopen
1Novel Plus
Jun 17, 2026
Aug 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
1Guest Management System Project
1Guest Management System
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability, which was classified as critical, has been found in SourceCodester Guest Management System. This issue affects some unknown processing of the file /guestmanagement/front.php. The manipulation of the argu...Show more
A vulnerability, which was classified as critical, has been found in SourceCodester Guest Management System. This issue affects some unknown processing of the file /guestmanagement/front.php. The manipulation of the argument rid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206489 was assigned to this vulnerability.Show less
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, wh...Show more
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.Show less
1Oretnom23
1Clinic's Patient Management System
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
1Mingsoft
1Mcms
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
1Mingsoft
1Mcms
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.
1Guest Management System Project
1Guest Management System
Jun 17, 2026
Aug 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username/pass leads to sql injec...Show more
A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username/pass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-206398 is the identifier assigned to this vulnerability.Show less
1Linuxfoundation
1Loopback Connector Postgresql
Jun 17, 2026
Aug 12, 2022
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to...Show more
Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the connected database. A patch was released in version 5.5.1. This affects users who does any of the following: - Connect to the database via the DataSource with `allowExtendedProperties: true` setting OR - Uses the connector's CRUD methods directly OR - Uses the connector's other methods to interpret the LoopBack filter. Users who are unable to upgrade should do the following if applicable: - Remove `allowExtendedProperties: true` DataSource setting - Add `allowExtendedProperties: false` DataSource setting - When passing directly to the connector functions, manually sanitize the user input for the `contains` LoopBack filter beforehand.Show less
1Update By Case Project
1Update By Case
Jun 17, 2026
Aug 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single database hit, using a case sql statement for it. Before version 0.1.3 `update_by_case` gem used custom sql...Show more
This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single database hit, using a case sql statement for it. Before version 0.1.3 `update_by_case` gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >= 0.1.3 that uses `Arel` instead to construct the resulting sql statement, with sanitized sql.Show less
1Phpgurukul
1Zoo Management System
Jun 17, 2026
Aug 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to...Show more
A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206249 was assigned to this vulnerability.Show less
1Gas Agency Management System Project
1Gas Agency Management System
Jun 17, 2026
Aug 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been found in SourceCodester Gas Agency Management System and classified as critical. This vulnerability affects unknown code of the file gasmark/login.php. The manipulation of the argument username l...Show more
A vulnerability has been found in SourceCodester Gas Agency Management System and classified as critical. This vulnerability affects unknown code of the file gasmark/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206248.Show less
1Automated Beer Parlour Billing System Project
1Automated Beer Parlour Billing System
Jun 17, 2026
Aug 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads t...Show more
A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-206247.Show less
1Student Information System Project
1Student Information System
Jun 17, 2026
Aug 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical was found in SourceCodester Student Information System. Affected by this vulnerability is an unknown functionality of the file /admin/students/view_student.php. The manipulation of...Show more
A vulnerability classified as critical was found in SourceCodester Student Information System. Affected by this vulnerability is an unknown functionality of the file /admin/students/view_student.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The identifier VDB-206245 was assigned to this vulnerability.Show less
1Google
1Android
Jun 17, 2026
Aug 12, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lead to local information disclosure of sms/mms data with User execution privileges needed. User intera...Show more
In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lead to local information disclosure of sms/mms data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204117261Show less
1Library Management System Project
1Library Management System
Jun 17, 2026
Aug 11, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in SourceCodester Library Management System. It has been declared as critical. This vulnerability affects unknown code of the file librarian/student.php. The manipulation of the argument title l...Show more
A vulnerability was found in SourceCodester Library Management System. It has been declared as critical. This vulnerability affects unknown code of the file librarian/student.php. The manipulation of the argument title leads to sql injection. The attack can be initiated remotely. VDB-206170 is the identifier assigned to this vulnerability.Show less