← Back
CWE-89

20,840 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,840)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Water Billing System Project
1Water Billing System
Jun 17, 2026
May 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id
1Chatbot App With Suggestion Project
1Chatbot App With Suggestion
Jun 17, 2026
May 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id.
1Badminton Center Management System Project
1Badminton Center Management System
Jun 17, 2026
May 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.
1Merchandise Online Store Project
1Merchandise Online Store
Jun 17, 2026
May 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product.
1Sscms
1Siteserver Cms
Jun 17, 2026
May 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
1Home Clean Services Management System Project
1Home Clean Services Management System
Jun 17, 2026
May 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affects the file login.php. The manipulation of the argument email with the input admin%'/**/AND/**/(SELEC...Show more
A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affects the file login.php. The manipulation of the argument email with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(2)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. The attack can be initiated remotely but it requires authentication. Exploit details have been disclosed to the public.Show less
1Home Clean Services Management System Project
1Home Clean Services Management System
Jun 17, 2026
May 24, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND...Show more
A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND/**/(SELECT/**/5383/**/FROM/**/(SELECT(SLEEP(5)))JPeh)/**/AND/**/'frfq%'='frfq leads to sql injection. It is possible to initiate the attack remotely but it requires authentication. Exploit details have been disclosed to the public.Show less
1Imgurl Project
1Imgurl
Jun 17, 2026
May 24, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.
1Inoutscripts
1Blockchain Altexchanger
Jun 17, 2026
May 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.
1Inoutscripts
1Blockchain Altexchanger
Jun 17, 2026
May 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.
1Inoutscripts
2Blockchain Altexchanger
Blockchain Fiatexchanger
Jun 17, 2026
May 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.
1Labarta
1Wp Contacts Manager
Jun 17, 2026
May 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.
1Nirweb
1Nirweb Support
Jun 17, 2026
May 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection
1Covid 19 Directory On Vaccination System Project
1Covid 19 Directory On Vaccination System
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.
1School Dormitory Management System Project
1School Dormitory Management System
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.
1Chatbot Application With A Suggestion Feature Project
1Chatbot Application With A Suggestion Feature
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.
1Online Sports Complex Booking System Project
1Online Sports Complex Booking System
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Sports Complex Booking System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /scbs/view_facility.php.
1Simple Student Quarterly Result/grade System Project
1Simple Student Quarterly Result/grade System
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.
1Multi Vendor Online Groceries Management System Project
1Multi Vendor Online Groceries Management System
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php.
1Online Sports Complex Booking System Project
1Online Sports Complex Booking System
Jun 17, 2026
May 19, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client.