← Back
CWE-89

20,857 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,857)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Admission System Project
1Online Admission System
Jun 17, 2026
Aug 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in SourceCodester Online Admission System and classified as critical. This issue affects some unknown processing of the component GET Parameter Handler. The manipulation of the argument eid lead...Show more
A vulnerability was found in SourceCodester Online Admission System and classified as critical. This issue affects some unknown processing of the component GET Parameter Handler. The manipulation of the argument eid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-205565 was assigned to this vulnerability.Show less
1Online Admission System Project
1Online Admission System
Jun 17, 2026
Aug 4, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been found in SourceCodester Online Admission System and classified as critical. This vulnerability affects unknown code of the component POST Parameter Handler. The manipulation of the argument shift...Show more
A vulnerability has been found in SourceCodester Online Admission System and classified as critical. This vulnerability affects unknown code of the component POST Parameter Handler. The manipulation of the argument shift leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this entry is VDB-205564.Show less
3Debian
FedoraprojectPostgresql
3Debian Linux
FedoraPostgresql Jdbc Driver
Jun 17, 2026
Aug 3, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method...Show more
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to SQL injection. This could lead to executing additional SQL commands as the application's JDBC user. User applications that do not invoke the `ResultSet.refreshRow()` method are not impacted. User application that do invoke that method are impacted if the underlying database that they are querying via their JDBC application may be under the control of an attacker. The attack requires the attacker to trick the user into executing SQL against a table name who's column names would contain the malicious SQL and subsequently invoke the `refreshRow()` method on the ResultSet. Note that the application's JDBC user and the schema owner need not be the same. A JDBC application that executes as a privileged user querying database schemas owned by potentially malicious less-privileged users would be vulnerable. In that situation it may be possible for the malicious user to craft a schema that causes the application to execute commands as the privileged user. Patched versions will be released as `42.2.26` and `42.4.1`. Users are advised to upgrade. There are no known workarounds for this issue.Show less
1Bmc
1Track It!
Jun 17, 2026
Aug 3, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists wit...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690.Show less
1Centreon
1Centreon
Jun 17, 2026
Aug 3, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of Virtual Metrics. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16336.Show less
1Centreon
1Centreon
Jun 17, 2026
Aug 3, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poll...Show more
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335.Show less
1Santesoft
1Sante Pacs Server
Jun 17, 2026
Aug 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the...Show more
This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of calls to the login endpoint. When parsing the username element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17331.Show less
1Percona
1Percona Server
Jun 17, 2026
Aug 3, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Aug 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
1Quest
1Kace Systems Management Appliance
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php.
1Web Based Quiz System Project
1Web Based Quiz System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php.
1Online Tours And Travels Management System Project
1Online Tours And Travels Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname parameter at /admin/operations/packages.php.
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php.
1Phptpoint
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php.
1Phptpoint
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php.
1Phptpoint
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.
1Phptpoint
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.
1Pharmacy Management System Project
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php.
1Pharmacy Management System Project
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php.