CWE-89
20,842 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,842)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Advanced School Management System Project 1Advanced School Management System Jun 17, 2026 Jun 15, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_parents_profile.php?my_index=. |
1Advanced School Management System Project 1Advanced School Management System Jun 17, 2026 Jun 15, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher_profile.php?my_index=. |
1Advanced School Management System Project 1Advanced School Management System Jun 17, 2026 Jun 15, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam_timetable.php?id=. |
1Advanced School Management System Project 1Advanced School Management System Jun 17, 2026 Jun 15, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_events.php?event_id=. |
1Advanced School Management System Project 1Advanced School Management System Jun 17, 2026 Jun 15, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_timetable.php?id=. |
1Online Tours And Travels Management System Project 1Online Tours And Travels Management System Jun 17, 2026 Jun 15, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname parameter at /admin/operations/tax.php. |
1Web Based Quiz System Project 1Web Based Quiz System Jun 17, 2026 Jun 15, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php. |
1Theme Park Ticketing System Project 1Theme Park Ticketing System Jun 17, 2026 Jun 15, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ticket.php. |
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php. |
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Action/Admin/MailAction.class.php. |
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/SiteAction.class.php. |
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php. |
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group can inject a malicious SQL query in order to affect the execution logic of the appl...Show more |
1Ibm 1Financial Transaction Manager Jun 17, 2026 Jun 15, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker...Show more |
1Bank Management System Project 1Bank Management System Jun 17, 2026 Jun 15, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected by this issue is login.php. The manipulation of the argument password with the input 1'and 1=2 unio...Show more |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/view_category.php?id=. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/manage_category.php?id=. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_category. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_inquiry. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=products/view_product&id=. |