CWE-89
20,818 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,818)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php. |
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php. |
1Attendance And Payroll System Project 1Attendance And Payroll System Jun 17, 2026 Apr 21, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php. |
1Cisco 1Unified Communications Manager Im And Presence Service Jun 17, 2026 Apr 21, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks...Show more |
Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they would not have normally run. |
1Webtareas Project 1Webtareas Jun 17, 2026 Apr 20, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. |
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. |
1Microfinance Management System Project 1Microfinance Management System Jun 17, 2026 Apr 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code...Show more |
1Daily Prayer Time Project 1Daily Prayer Time Jun 17, 2026 Apr 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users),...Show more |
Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make aut...Show more |
2Open Emr Phpgacl Project2Openemr PhpgaclJun 17, 2026 Apr 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability. |
1Automatic Question Paper Generator Project 1Automatic Question Paper Generator Jun 17, 2026 Apr 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module. |
Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php. |
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy. |
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan. |
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del. |
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy. |
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del. |
Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an attacker must inject '"> on the thes1 parameter. |