CWE-89
20,856 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,856)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection. |
The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection. |
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Jul 12, 2022 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from th...Show more |
1Oretnom23 1Clinic's Patient Management System Jun 17, 2026 Jul 12, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Lo...Show more |
1Online Hotel Booking Project 1Online Hotel Booking Jun 17, 2026 Jul 12, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in Online Hotel Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file edit_room_cat.php of the component Room Handler. The manipulation...Show more |
1Online Hotel Booking Project 1Online Hotel Booking Jun 17, 2026 Jul 12, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The ma...Show more |
1Varktech 1Pricing Deals For Woocommerce Jun 17, 2026 Jul 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a...Show more |
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add,...Show more |
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. H...Show more |
1Atoms183 Cms Project 1Atoms183 Cms Jun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php. |
1Online Accreditation Management System Project 1Online Accreditation Management System Jun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter at process.php. |
Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=search/rentals. |
Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor Management Kiosk, an application designe...Show more |
Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any authenticated user, in any kind of rule....Show more |
1So Filter Shop By Project 1So Filter Shop By Jun 17, 2026 Jul 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_fil...Show more |
1Ingredient Stock Management System Project 1Ingredient Stock Management System Jun 17, 2026 Jul 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php. |
1Newsletter Module Project 1Newsletter Module Jun 17, 2026 Jul 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php. |
Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category. |
SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of al...Show more |
SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper with existing data, allow the complete dis...Show more |