← Back
CWE-89

20,840 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,840)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.
1Chshcms
1Cscms Music Portal System
Jun 17, 2026
May 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.
174cms
174cmsse
Jun 17, 2026
May 26, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
1Piwigo
1Piwigo
Jun 17, 2026
May 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
1Nokia
1Broadcast Message Center
Jun 17, 2026
May 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifi...Show more
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data.Show less
2Online Food Ordering System Project
Oretnom23
2Online Food Ordering System
Online Food Ordering System
Jun 17, 2026
May 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.
1Archibus
1Web Central
Jun 17, 2026
May 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify que...Show more
In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database. This is fixed in all recent versions, such as version 26.2.Show less
1Camptocamp
1Terraboard
Jun 17, 2026
May 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.
1Ibm
1I
Jun 17, 2026
May 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. I...Show more
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.Show less
1Telecomsoftware
2Samwin Agent
Samwin Contact Center
Nov 21, 2024
May 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability classified as critical has been found in Telecommunication Software SAMwin Contact Center Suite 5.1. This affects the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the database handler. T...Show more
A vulnerability classified as critical has been found in Telecommunication Software SAMwin Contact Center Suite 5.1. This affects the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the database handler. The manipulation leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Room Rent Portal Site Project
1Room Rent Portal Site
Jun 17, 2026
May 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id.
1Covid 19 Travel Pass Management System Project
1Covid 19 Travel Pass Management System
Jun 17, 2026
May 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
May 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.