← Back
CWE-89

20,842 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,842)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hospital's Patient Records Management System Project
1Hospital's Patient Records Management System
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/view_doctor.php?id=.
1Hospital's Patient Records Management System Project
1Hospital's Patient Records Management System
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/manage_doctor.php?id=.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_menu.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jun 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.
1Online Fire Reporting System Project
1Online Fire Reporting System
Jun 17, 2026
Jun 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.
1South Gate Inn Online Reservation System Project
1South Gate Inn Online Reservation System
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vuln...Show more
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function. This vulnerability leads to remote code execution.Show less
1Church Management System Project
1Church Management System
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on th...Show more
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.Show less
1Amodat
1Mobile Application Gateway
Jun 17, 2026
Jun 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.
1Amodat
1Mobile Application Gateway
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'--
1Carrcommunications
1Rsvpmaker
Jun 17, 2026
Jun 13, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file....Show more
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.Show less
1Rosariosis
1Rosariosis
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
1Soflyy
1Export Any Wordpress Data To Xml/csv
Jun 17, 2026
Jun 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
1Presspage
1Bestbooks
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
1Iqonic
1Kivicare
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections explo...Show more
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated usersShow less
1Vendavo
1Pricepoint
Nov 21, 2024
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been found in Navetti PricePoint 4.6.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection (Blind). The attack can be laun...Show more
A vulnerability has been found in Navetti PricePoint 4.6.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection (Blind). The attack can be launched remotely. Upgrading to version 4.7.0.0 is able to address this issue. It is recommended to upgrade the affected component.Show less