← Back
CWE-89

20,849 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,849)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.
1Ideaco
1Ideatms
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO
1Docebo
1Docebo
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
1Laiketui
1Laiketui
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.
1Laiketui
1Laiketui
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection exists in LaiKetui v3.5.0 the background administrator list.
1Maxb
1Maxboard
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php.
1Hindu Matrimonial Script Project
1Hindu Matrimonial Script
Nov 21, 2024
Jun 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password...Show more
A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1E Dynamics
1Events Made Easy
Jun 17, 2026
Jun 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
1Codesolz
1Better Find And Replace
Jun 17, 2026
Jun 20, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
1Asus
1Control Center
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.
1Rescue Dispatch Management System Project
1Rescue Dispatch Management System
Jun 17, 2026
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=.
1Online Ordering System Project
1Online Ordering System
Jun 17, 2026
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
1Online Ordering System Project
1Online Ordering System
Jun 17, 2026
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
1Online Ordering System Project
1Online Ordering System
Jun 17, 2026
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.