← Back
CWE-89

20,793 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,793)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Php Cms Project
1Php Cms
Jun 17, 2026
Apr 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.
1Fortinet
1Fortiwan
Jun 17, 2026
Apr 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted...Show more
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.Show less
1Payroll Management System Project
1Payroll Management System
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
1Online Student Admission Project
1Online Student Admission
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter.
1Online Banking System Project
1Online Banking System
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
1Online Sports Complex Booking Project
1Online Sports Complex Booking
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
1Oretnom23
1Student Grading System
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
1Angeljudesuarez
1Insurance Management System
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
1Employee Performance Evaluation Project
1Employee Performance Evaluation
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
1Matrimony Project
1Matrimony
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter.
1Impresscms
1Impresscms
Jun 17, 2026
Apr 5, 2022
N/A· v4
7.2 HIGH· v3
8.5 HIGH· v2
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the applicat...Show more
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.Show less
1Simple Student Information System Project
1Simple Student Information System
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student.
1Mingsoft
1Mcms
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
1Cybernetikz
1Easy Social Icons
Jun 17, 2026
Apr 4, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.
1Auvesy Mdt
2Autosave
Autosave For System Platform
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML....Show more
A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the executable and is therefore vulnerable to binary hijacking.Show less
1Auvesy Mdt
2Autosave
Autosave For System Platform
Jun 17, 2026
Apr 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.
1Pagekit
1Pagekit
Jun 17, 2026
Apr 1, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
Mar 31, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Mar 31, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
Mar 31, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.