← Back
CWE-89

20,818 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,818)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Attendance And Payroll System Project
1Attendance And Payroll System
Jun 17, 2026
Apr 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php.
1Attendance And Payroll System Project
1Attendance And Payroll System
Jun 17, 2026
Apr 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php.
1Attendance And Payroll System Project
1Attendance And Payroll System
Jun 17, 2026
Apr 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.
1Cisco
1Unified Communications Manager Im And Presence Service
Jun 17, 2026
Apr 21, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks...Show more
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain data or modify data that is stored in the underlying database of the affected system.Show less
1Blazer Project
1Blazer
Jun 17, 2026
Apr 21, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they would not have normally run.
1Webtareas Project
1Webtareas
Jun 17, 2026
Apr 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
1Formalms
1Formalms
Jun 17, 2026
Apr 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.
1Microfinance Management System Project
1Microfinance Management System
Jun 17, 2026
Apr 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code...Show more
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.Show less
1Daily Prayer Time Project
1Daily Prayer Time
Jun 17, 2026
Apr 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users),...Show more
The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injectionShow less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Apr 18, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make aut...Show more
Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities, this can be done either with administrator credentials or through cross-site request forgery.Show less
2Open Emr
Phpgacl Project
2Openemr
Phpgacl
Jun 17, 2026
Apr 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
1Automatic Question Paper Generator Project
1Automatic Question Paper Generator
Jun 17, 2026
Apr 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Apr 18, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.
1Chamilo
1Chamilo Lms
Jun 17, 2026
Apr 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.
1Chshcms
1Cscms
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy.
1Chshcms
1Cscms
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.
1Chshcms
1Cscms
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.
1Chshcms
1Cscms
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.
1Chshcms
1Cscms
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.
1Wecul
1Nyron
Jun 17, 2026
Apr 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an attacker must inject '"> on the thes1 parameter.