CWE-89
20,842 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,842)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=user/manage_user&id=. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/manage_field_order.php?id=. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=inquiries/view_inquiry&id=. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/fields/view_field.php?id=. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/fields/manage_field.php?id=. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=products/manage_product&id=. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_message. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room_type. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_history. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_doctor. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/view_room.php?id=. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/manage_room.php?id=. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via hprms/admin/room_types/manage_room_type.php?id=. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/room_types/view_room_type.php?id=. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=user/manage_user&id=. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=patients/view_patient&id=. |