← Back
CWE-89

20,840 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,840)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Sports Complex Booking System Project
1Online Sports Complex Booking System
Jun 17, 2026
May 19, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /classes/master.php?f=delete_ Facility.
1Online Sports Complex Booking System Project
1Online Sports Complex Booking System
Jun 17, 2026
May 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client.
1Spip
1Spip
Jun 17, 2026
May 19, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where parameters.
1Grandcom
1Dynweb
Jun 17, 2026
May 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the...Show more
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.Show less
3Fedoraproject
MoodleRedhat
3Enterprise Linux
FedoraMoodle
Jun 17, 2026
May 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
1Cambiumnetworks
1Cnmaestro
Jun 17, 2026
May 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user...Show more
The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.Show less
1Cambiumnetworks
1Cnmaestro
Jun 17, 2026
May 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro da...Show more
The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.Show less
1Covid 19 Travel Pass Management Project
1Covid 19 Travel Pass Management
Jun 17, 2026
May 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks.
1Oretnom23
1Toll Tax Management System
Jun 17, 2026
May 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks.
1Home Clean Service System Project
1Home Clean Service System
Jun 17, 2026
May 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks.
1Fidelissecurity
2Deception
Network
Jun 17, 2026
May 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions pri...Show more
Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.Show less
1Allgeier
1Metasonic Doc Webclient
Jun 17, 2026
May 16, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.
1Visual Slide Box Builder Project
1Visual Slide Box Builder
Jun 17, 2026
May 16, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as s...Show more
The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as subscriber), leading to SQL InjectionsShow less
1Reputeinfosystems
1Pricing Table
Jun 17, 2026
May 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthen...Show more
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated usersShow less
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
May 16, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
May 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
1Janeczku
1Calibre Web
Jun 17, 2026
May 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Calibre-Web before 0.6.18 allows user table SQL Injection.
1Erp Pro Project
1Erp Pro
Jun 17, 2026
May 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml..
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
May 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php.
1Churchcrm
1Churchcrm
Jun 17, 2026
May 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used...Show more
A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being performed.Show less