← Back
CWE-89

20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,790)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elbtide
1Advanced Booking Calendar
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unau...Show more
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injectionShow less
1Taogogo
1Taocms
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php.
1Wvti
1One Card Integrated Management System
Jun 17, 2026
Mar 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection.
1Piwigo
1Piwigo
Jun 17, 2026
Mar 18, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.
1Foliovision
1Fv Flowplayer Video Player
Jun 17, 2026
Mar 18, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
1Rapid7
1Nexpose
Jun 17, 2026
Mar 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manip...Show more
Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manipulate the "ANY" and "OR" operators in the SearchCriteria and inject SQL code. This issue was fixed in Rapid7 Nexpose version 6.6.129.Show less
1Attendance And Payroll System Project
1Attendance And Payroll System
Jul 9, 2026
Mar 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
1Slims
1Senayan Library Management System
Jun 17, 2026
Mar 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.
1Slims
1Senayan Library Management System
Jun 17, 2026
Mar 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
1Slims
1Senayan Library Management System
Jun 17, 2026
Mar 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through...Show more
Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used by remotely authenticated librarian users.Show less
1Online Project Time Management System Project
1Online Project Time Management System
Jun 17, 2026
Mar 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.
1Btiteam
1Xbtit
Jun 17, 2026
Mar 16, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data such...Show more
A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data such as usernames and passwords and in some cases use this vulnerability in order to get a remote code execution on the remote web server.Show less
1Online Banking System Project
1Online Banking System
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Mar 15, 2022
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
1Thedigitalcraft
1Atomcms
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.
1Sylius
1Syliusgridbundle
Jun 17, 2026
Mar 15, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not k...Show more
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took steps to remediate the vulnerability. The issue is fixed in versions 1.10.1 and 1.11-rc2. As a workaround, overwrite the`Sylius\Component\Grid\Sorting\Sorter.php` class and register it in the container. More information about this workaround is available in the GitHub Security Advisory.Show less
1Sedlex
1Simple Quotation
Jun 17, 2026
Mar 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenti...Show more
The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenticated users, such as subscriber to perform SQL injection attacksShow less
1Wielebenwir
1Commonsbooking
Jun 17, 2026
Mar 14, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL...Show more
The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injectionShow less