← Back
CWE-89

20,842 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,842)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advanced School Management System Project
1Advanced School Management System
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_parents_profile.php?my_index=.
1Advanced School Management System Project
1Advanced School Management System
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher_profile.php?my_index=.
1Advanced School Management System Project
1Advanced School Management System
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam_timetable.php?id=.
1Advanced School Management System Project
1Advanced School Management System
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_events.php?event_id=.
1Advanced School Management System Project
1Advanced School Management System
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_timetable.php?id=.
1Online Tours And Travels Management System Project
1Online Tours And Travels Management System
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname parameter at /admin/operations/tax.php.
1Web Based Quiz System Project
1Web Based Quiz System
Jun 17, 2026
Jun 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php.
1Theme Park Ticketing System Project
1Theme Park Ticketing System
Jun 17, 2026
Jun 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ticket.php.
1Youdiancms
1Youdiancms
Jun 17, 2026
Jun 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php.
1Youdiancms
1Youdiancms
Jun 17, 2026
Jun 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Action/Admin/MailAction.class.php.
1Youdiancms
1Youdiancms
Jun 17, 2026
Jun 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/SiteAction.class.php.
1Kkcms Project
1Kkcms
Jun 17, 2026
Jun 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.
1Peel
1Peel Shopping
Jul 9, 2026
Jun 15, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the appl...Show more
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the application and retrive information from the database.Show less
1Ibm
1Financial Transaction Manager
Jun 17, 2026
Jun 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker...Show more
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 166801.Show less
1Bank Management System Project
1Bank Management System
Jun 17, 2026
Jun 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected by this issue is login.php. The manipulation of the argument password with the input 1'and 1=2 unio...Show more
A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected by this issue is login.php. The manipulation of the argument password with the input 1'and 1=2 union select 1,sleep(10),3,4,5 --+ leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Product Show Room Site Project
1Product Show Room Site
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/view_category.php?id=.
1Product Show Room Site Project
1Product Show Room Site
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/manage_category.php?id=.
1Product Show Room Site Project
1Product Show Room Site
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_category.
1Product Show Room Site Project
1Product Show Room Site
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_inquiry.
1Product Show Room Site Project
1Product Show Room Site
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=products/view_product&id=.