← Back
CWE-89

20,841 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,841)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Maxb
1Maxboard
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and i...Show more
SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file.Show less
1Zzcms
1Zzcms
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.
1Dhis2
1Dhis 2
Jun 17, 2026
Jun 1, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?programs=` API endpoint in DHIS2 versions p...Show more
DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?programs=` API endpoint in DHIS2 versions prior to 2.36.10.1 and 2.37.6.1. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user and requires a conscious attack to be exploited. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance's database. Security patches are now available for DHIS2 versions 2.36.10.1 and 2.37.6.1. One may apply mitigations at the web proxy level as a workaround. More information about these mitigations is available in the GitHub Security Advisory.Show less
1Era404
1Stafflist
Jun 17, 2026
May 30, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
May 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
May 26, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege esc...Show more
In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation).Show less
1Jflyfox
1Jfinal Cms
Jun 17, 2026
May 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.