← Back
CWE-89

20,856 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,856)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oliverklee
1Seminars
Jun 17, 2026
Jul 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.
1Oliverklee
1Oelib
Jun 17, 2026
Jul 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.
1Sap
1Business Objects Business Intelligence Platform
Jun 17, 2026
Jul 12, 2022
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from th...Show more
SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from the SQL backend. On successful exploitation, the attacker can cause limited impact on confidentiality and integrity of the applicationShow less
1Oretnom23
1Clinic's Patient Management System
Jun 17, 2026
Jul 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Lo...Show more
A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Login Page. The manipulation of the argument user_name with the input admin' or '1'='1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Online Hotel Booking Project
1Online Hotel Booking
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in Online Hotel Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file edit_room_cat.php of the component Room Handler. The manipulation...Show more
A vulnerability was found in Online Hotel Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file edit_room_cat.php of the component Room Handler. The manipulation of the argument roomname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Online Hotel Booking Project
1Online Hotel Booking
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The ma...Show more
A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The manipulation of the argument id with the input 2828%27%20AND%20(SELECT%203766%20FROM%20(SELECT(SLEEP(5)))BmIK)%20AND%20%27YLPl%27=%27YLPl leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Varktech
1Pricing Deals For Woocommerce
Jun 17, 2026
Jul 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a...Show more
The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injectionShow less
1Ibm
1Security Verify Access
Jun 17, 2026
Jul 8, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add,...Show more
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 225079.Show less
1Hpe
1Icewall Sso Certd
Jun 17, 2026
Jul 8, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. H...Show more
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd library Patch 9 for HP-UX.Show less
1Atoms183 Cms Project
1Atoms183 Cms
Jun 17, 2026
Jul 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.
1Online Accreditation Management System Project
1Online Accreditation Management System
Jun 17, 2026
Jul 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter at process.php.
1Nesote
1Inout Homestay
Jun 17, 2026
Jul 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=search/rentals.
1Gallagher
1Command Centre
Jun 17, 2026
Jul 6, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor Management Kiosk, an application designe...Show more
Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor Management Kiosk, an application designed for public use, to invoke an arbitrary SQL query that has been preloaded into the registry of the Windows Server to obtain sensitive information. This issue affects: Gallagher Command Centre 8.60 versions prior to 8.60.1652; 8.50 versions prior to 8.50.2245; 8.40 versions prior to 8.40.2216; 8.30 versions prior to 8.30.1470; version 8.20 and prior versions.Show less
1Agilepoint
1Agilepoint Nx
Jun 17, 2026
Jul 6, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any authenticated user, in any kind of rule....Show more
Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any authenticated user, in any kind of rule. under the function : /AgilePointServer/Extension/FetchUsingEncodedData in the parameter: EncodedDataShow less
1So Filter Shop By Project
1So Filter Shop By
Jun 17, 2026
Jul 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_fil...Show more
So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.Show less
1Ingredient Stock Management System Project
1Ingredient Stock Management System
Jun 17, 2026
Jul 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php.
1Newsletter Module Project
1Newsletter Module
Jun 17, 2026
Jul 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
1Taogogo
1Taocms
Jun 17, 2026
Jul 5, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
1Vicidial
1Vicidial
Jun 17, 2026
Jul 5, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of al...Show more
SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server.Show less
1Vicidial
1Vicidial
Jun 17, 2026
Jul 5, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper with existing data, allow the complete dis...Show more
SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.Show less