← Back
CWE-89

20,856 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,856)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vicidial
1Vicidial
Jun 17, 2026
Jul 5, 2022
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email parameters allows attacker to spoof identity, tamper with existing data,...Show more
SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email parameters allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.Show less
1Djangoproject
1Django
Jun 17, 2026
Jul 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that...Show more
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.Show less
1Typeorm
1Typeorm
Jun 17, 2026
Jul 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead...Show more
The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validationShow less
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Jul 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Jul 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Jul 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php.
1Viaviweb
1Ebook
Jun 17, 2026
Jul 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books) 10 via the author_id parameter to api.php.
1Bestsoftinc
1Online Hotel Booking System
Nov 21, 2024
Jun 30, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid...Show more
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Bestsoftinc
1Online Hotel Booking System
Nov 21, 2024
Jun 30, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to...Show more
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 29, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 29, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 29, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_train.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 29, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_message.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 29, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.
1Enalean
1Tuleap
Jun 17, 2026
Jun 29, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retr...Show more
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the capability to create a new tracker can execute arbitrary SQL queries. Users are advised to upgrade. There is no known workaround for this issue.Show less
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 29, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php.
1Glpi Project
1Glpi
Jun 17, 2026
Jun 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible o...Show more
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions there is a SQL injection vulnerability which is possible on login page. No user credentials are required to exploit this vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Jun 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql in...Show more
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and all affected users are advised to upgrade.Show less
1Shopex
1Ecshop
Jun 17, 2026
Jun 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
1Simplessus
1Simplessus
Nov 21, 2024
Jun 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in Simplessus 3.7.7. It has been declared as critical. This vulnerability affects unknown code of the component Cookie Handler. The manipulation of the argument UWA_SID leads to sql injection (T...Show more
A vulnerability was found in Simplessus 3.7.7. It has been declared as critical. This vulnerability affects unknown code of the component Cookie Handler. The manipulation of the argument UWA_SID leads to sql injection (Time). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.8.3 is able to address this issue. It is recommended to upgrade the affected component.Show less