CWE-89
20,824 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,824)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Home Owners Collection Management System Project 1Home Owners Collection Management System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection. |
1Home Owners Collection Management System Project 1Home Owners Collection Management System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member. |
1Car Driving School Management System Project 1Car Driving School Management System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment. |
1Car Driving School Management System Project 1Car Driving School Management System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package. |
1Simple Real Estate Portal System Portal 1Simple Real Estate Portal System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent. |
1Simple Real Estate Portal System Project 1Simple Real Estate Portal System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent. |
1Simple Real Estate Portal System Project 1Simple Real Estate Portal System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate. |
1Simple Real Estate Portal System Project 1Simple Real Estate Portal System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type. |
1Simple Real Estate Portal System Project 1Simple Real Estate Portal System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity. |
1Oretnom23 1Student Grading System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=. |
1Oretnom23 1Student Grading System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year. |
1Oretnom23 1Student Grading System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade. |
1Purchase Order Management System Project 1Purchase Order Management System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier. |
1Purchase Order Management System Project 1Purchase Order Management System Jun 17, 2026 Apr 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item. |
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_edit.php. |
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php. |
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php. |
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php. |
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php. |
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php. |