CWE-89
20,842 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,842)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/view_doctor.php?id=. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/manage_doctor.php?id=. |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=. |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=. |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=. |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category. |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=. |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Jun 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_menu. |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=. |
1Online Fire Reporting System Project 1Online Fire Reporting System Jun 17, 2026 Jun 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php. |
1South Gate Inn Online Reservation System Project 1South Gate Inn Online Reservation System Jun 17, 2026 Jun 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vuln...Show more |
1Church Management System Project 1Church Management System Jun 17, 2026 Jun 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on th...Show more |
1Amodat 1Mobile Application Gateway Jun 17, 2026 Jun 13, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel. |
1Amodat 1Mobile Application Gateway Jun 17, 2026 Jun 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'-- |
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file....Show more |
SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0. |
1Soflyy 1Export Any Wordpress Data To Xml/csv Jun 17, 2026 Jun 13, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability. |
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users |
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections explo...Show more |
A vulnerability has been found in Navetti PricePoint 4.6.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection (Blind). The attack can be laun...Show more |