← Back
CWE-89

20,849 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,849)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Discussion Forum Project
1Online Discussion Forum
Jun 17, 2026
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.
1Voipmonitor
1Voipmonitor
Jun 17, 2026
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.
1Victor Cms Project
1Victor Cms
Jun 17, 2026
Jun 16, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.
1Nokia
1Vitalsuite
Jun 17, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
1Phpgurukul
1Directory Management System
Jul 9, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
1Phpgurukul
1Directory Management System
Jul 9, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
1Phpgurukul
1Directory Management System
Jul 9, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
1Online Tutor Portal Site Project
1Online Tutor Portal Site
Jun 17, 2026
Jun 16, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
1Razormist
1Online Discussion Forum Site
Jun 17, 2026
Jun 16, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
1Student Registration And Fee Payment System Project
1Student Registration And Fee Payment System
Jun 17, 2026
Jun 16, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
1Advanced School Management System Project
1Advanced School Management System
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=.