CWE-89
20,849 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,849)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map. |
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list. |
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index. |
IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO |
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained. |
SQL injection exists in LaiKetui v3.5.0 the background administrator list. |
Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation. |
1Online Railway Reservation System Project 1Online Railway Reservation System Jun 17, 2026 Jun 21, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php. |
1Online Railway Reservation System Project 1Online Railway Reservation System Jun 17, 2026 Jun 21, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php. |
1Online Railway Reservation System Project 1Online Railway Reservation System Jun 17, 2026 Jun 21, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user. |
1Online Railway Reservation System Project 1Online Railway Reservation System Jun 17, 2026 Jun 21, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php. |
1Hindu Matrimonial Script Project 1Hindu Matrimonial Script Nov 21, 2024 Jun 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password...Show more |
1E Dynamics 1Events Made Easy Jun 17, 2026 Jun 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection |
1Codesolz 1Better Find And Replace Jun 17, 2026 Jun 20, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection |
ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data. |
1Rescue Dispatch Management System Project 1Rescue Dispatch Management System Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=. |