← Back
CWE-89

20,856 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,856)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pharmacy Management System Project
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php.
1Pharmacy Management System Project
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.
1Pharmacy Management System Project
1Pharmacy Management System
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.
1Prestashop
1Prestashop
Jun 17, 2026
Aug 1, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. T...Show more
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.Show less
1Kainelabs
1Youzify
Jun 17, 2026
Aug 1, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
1Sonicwall
2Analytics
Global Management System
Jun 17, 2026
Jul 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520 and earlier versions.
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Jul 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability classified as critical was found in SourceCodester Garage Management System 1.0. This vulnerability affects unknown code of the file /edituser.php. The manipulation of the argument id with the input -2'%2...Show more
A vulnerability classified as critical was found in SourceCodester Garage Management System 1.0. This vulnerability affects unknown code of the file /edituser.php. The manipulation of the argument id with the input -2'%20UNION%20select%2011,user(),333,444--+ leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Inavitas
1Solar Log
Jun 17, 2026
Jul 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.
1Barangay Management System Project
1Barangay Management System
Jun 17, 2026
Jul 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php.
1Synology
1Carddav Server
Jun 17, 2026
Jul 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server before 6.0.10-0153 allows remote authenticated users to inject SQL command...Show more
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server before 6.0.10-0153 allows remote authenticated users to inject SQL commands via unspecified vectors.Show less
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
1Fruits Bazar Project
1Fruits Bazar
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.
1Oretnom23
1Warehouse Management System
Jun 17, 2026
Jul 26, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.
1Online Fire Reporting System Project
1Online Fire Reporting System
Jun 17, 2026
Jul 26, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.
2Codepress
Plugins Market
2Visitor Statistics
Wp Visitor Statistics
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
1Communilink
1Clink Office
Jul 9, 2026
Jul 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.
1Dataease
1Dataease
Jun 17, 2026
Jul 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
1Supsystic
1Social Share Buttons
Jun 17, 2026
Jul 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
1Homepage Product Organizer For Woocommerce Project
1Homepage Product Organizer For Woocommerce
Jun 17, 2026
Jul 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.
1Ambit
1Movie Portal Script
Nov 21, 2024
Jul 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability, which was classified as critical, has been found in Itech Movie Portal Script 7.36. This issue affects some unknown processing of the file /film-rating.php. The manipulation of the argument v leads to sq...Show more
A vulnerability, which was classified as critical, has been found in Itech Movie Portal Script 7.36. This issue affects some unknown processing of the file /film-rating.php. The manipulation of the argument v leads to sql injection (Error). The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less