← Back
CWE-89

20,840 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,840)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.
1Waimairencms Project
1Waimairencms
Jun 17, 2026
May 11, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
1Shopwind
1Shopwind
Jun 17, 2026
May 11, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php
1Mingsoft
1Mcms
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
1Mingsoft
1Mcms
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
1Phpgurukul
1Cyber Cafe Management System
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
1Phpgurukul
1Dairy Farm Shop Management System
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
1Phpgurukul
1Directory Management System
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
1Wedding Management System Project
1Wedding Management System
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.
1Simple Bus Ticket Booking System Project
1Simple Bus Ticket Booking System
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.
1Complete Online Job Search System Project
1Complete Online Job Search System
Jun 17, 2026
May 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.
1Fortinet
1Fortinac
Jun 17, 2026
May 11, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8...Show more
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.Show less
1Carrcommunications
1Rsvpmaker
Jun 17, 2026
May 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This...Show more
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6.Show less
1Carrcommunications
1Rsvpmaker
Jun 17, 2026
May 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it...Show more
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.Show less