CWE-89
20,790 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,790)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Elbtide 1Advanced Booking Calendar Jun 17, 2026 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unau...Show more |
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php. |
1Wvti 1One Card Integrated Management System Jun 17, 2026 Mar 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection. |
Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php. |
1Foliovision 1Fv Flowplayer Video Player Jun 17, 2026 Mar 18, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727). |
Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manip...Show more |
1Attendance And Payroll System Project 1Attendance And Payroll System Jul 9, 2026 Mar 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters. |
1Slims 1Senayan Library Management System Jun 17, 2026 Mar 17, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained. |
1Slims 1Senayan Library Management System Jun 17, 2026 Mar 17, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained. |
1Slims 1Senayan Library Management System Jun 17, 2026 Mar 17, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through...Show more |
1Online Project Time Management System Project 1Online Project Time Management System Jun 17, 2026 Mar 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php. |
A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data such...Show more |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Mar 15, 2022 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Mar 15, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php. |
Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php. |
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not k...Show more |
The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX actions and is lacking escaping of user data when using it in SQL statements, allowing any authenti...Show more |
The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL...Show more |