CWE-89
20,841 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,841)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Jun 2, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Jun 2, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Jun 2, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Jun 2, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. |
1School Dormitory Management System Project 1School Dormitory Management System Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31. |
1School Dormitory Management System Project 1School Dormitory Management System Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4. |
1School Dormitory Management System Project 1School Dormitory Management System Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59. |
SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information. |
1Badminton Center Management System Project 1Badminton Center Management System Jul 9, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php. |
1Food Order And Table Reservation System Project 1Food Order And Table Reservation System Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters. |
1Ecommerce Project With Php And Mysqli Fruits Bazar Project 1Ecommerce Project With Php And Mysqli Fruits Bazar Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters. |
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script. |
1Responsive Online Blog Project 1Responsive Online Blog Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php. |
1Aceware 1Aceweb Online Portal Jul 9, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp. |
1Egavilanmedia 1Expense Management System Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database. |
1Contact Form With Messages Entry Management Project 1Contact Form With Messages Entry Management Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database. |
1Egavilanmedia 1User Registration And Login System With Admin Panel Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database. |
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege e...Show more |