CWE-89
20,849 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,849)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Discussion Forum Project 1Online Discussion Forum Jun 17, 2026 Jun 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php. |
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter. |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie. |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter. |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter. |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter. |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter. |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter. |
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie. |
1Victor Cms Project 1Victor Cms Jun 17, 2026 Jun 16, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php. |
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'. |
1Phpgurukul 1Directory Management System Jul 9, 2026 Jun 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php. |
1Phpgurukul 1Directory Management System Jul 9, 2026 Jun 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php. |
1Phpgurukul 1Directory Management System Jul 9, 2026 Jun 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php. |
1Online Tutor Portal Site Project 1Online Tutor Portal Site Jun 17, 2026 Jun 16, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team. |
1Razormist 1Online Discussion Forum Site Jun 17, 2026 Jun 16, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team. |
1Student Registration And Fee Payment System Project 1Student Registration And Fee Payment System Jun 17, 2026 Jun 16, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php. |
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php |
1Advanced School Management System Project 1Advanced School Management System Jun 17, 2026 Jun 15, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=. |