CWE-89
20,840 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,840)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Water Billing System Project 1Water Billing System Jun 17, 2026 May 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id |
1Chatbot App With Suggestion Project 1Chatbot App With Suggestion Jun 17, 2026 May 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id. |
1Badminton Center Management System Project 1Badminton Center Management System Jun 17, 2026 May 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id. |
1Merchandise Online Store Project 1Merchandise Online Store Jun 17, 2026 May 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product. |
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. |
1Home Clean Services Management System Project 1Home Clean Services Management System Jun 17, 2026 May 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affects the file login.php. The manipulation of the argument email with the input admin%'/**/AND/**/(SELEC...Show more |
1Home Clean Services Management System Project 1Home Clean Services Management System Jun 17, 2026 May 24, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unknown part of admin/login.php. The manipulation of the argument username with the input admin%'/**/AND...Show more |
imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost. |
1Inoutscripts 1Blockchain Altexchanger Jun 17, 2026 May 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection. |
1Inoutscripts 1Blockchain Altexchanger Jun 17, 2026 May 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection. |
1Inoutscripts 2Blockchain Altexchanger Blockchain FiatexchangerJun 17, 2026 May 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection. |
1Labarta 1Wp Contacts Manager Jun 17, 2026 May 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability. |
The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection |
1Covid 19 Directory On Vaccination System Project 1Covid 19 Directory On Vaccination System Jun 17, 2026 May 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field. |
1School Dormitory Management System Project 1School Dormitory Management System Jun 17, 2026 May 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php. |
1Chatbot Application With A Suggestion Feature Project 1Chatbot Application With A Suggestion Feature Jun 17, 2026 May 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php. |
1Online Sports Complex Booking System Project 1Online Sports Complex Booking System Jun 17, 2026 May 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Sports Complex Booking System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /scbs/view_facility.php. |
1Simple Student Quarterly Result/grade System Project 1Simple Student Quarterly Result/grade System Jun 17, 2026 May 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php. |
1Multi Vendor Online Groceries Management System Project 1Multi Vendor Online Groceries Management System Jun 17, 2026 May 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php. |
1Online Sports Complex Booking System Project 1Online Sports Complex Booking System Jun 17, 2026 May 19, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client. |