CWE-89
20,840 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,840)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan. |
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos. |
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. |
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save. |
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save. |
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy. |
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save. |
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save. |
1Chshcms 1Cscms Music Portal System Jun 17, 2026 May 26, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. |
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. |
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter. |
1Nokia 1Broadcast Message Center Jun 17, 2026 May 25, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifi...Show more |
2Online Food Ordering System Project Oretnom232Online Food Ordering System Online Food Ordering SystemJun 17, 2026 May 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php. |
In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify que...Show more |
SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0. |
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. I...Show more |
1Telecomsoftware 2Samwin Agent Samwin Contact CenterNov 21, 2024 May 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability classified as critical has been found in Telecommunication Software SAMwin Contact Center Suite 5.1. This affects the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the database handler. T...Show more |
1Room Rent Portal Site Project 1Room Rent Portal Site Jun 17, 2026 May 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id. |
1Covid 19 Travel Pass Management System Project 1Covid 19 Travel Pass Management System Jun 17, 2026 May 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status |
1Automotive Shop Management System Project 1Automotive Shop Management System Jun 17, 2026 May 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product. |