← Back
CWE-89

20,787 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,787)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
Jun 17, 2026
Jan 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
1Nextcloud
1Nextcloud
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers `FileContent...Show more
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers `FileContentProvider` and `DiskLruImageCacheFileProvider` have security issues (an SQL injection, and an insufficient permission control, respectively) that allow malicious apps in the same device to access Nextcloud's data bypassing the permission control system. Users should upgrade to version 3.18.1 to receive a patch. There are no known workarounds aside from upgrading.Show less
1Jeecg
1Jeecg Boot
Jun 17, 2026
Jan 25, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
1Iresturant Project
1Iresturant
Jun 17, 2026
Jan 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.
1Iresturant Project
1Iresturant
Jun 17, 2026
Jan 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.
1Online Project Time Management System Project
1Online Project Time Management System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.
1Online Payment Hub Project
1Online Payment Hub
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.
1Try My Recipe Project
1Try My Recipe
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.
1Patient Appointment Scheduler System Project
1Patient Appointment Scheduler System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
1Oretnom23
1Banking System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Jan 24, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to inject unfiltered SQL into the DLP part o...Show more
SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to inject unfiltered SQL into the DLP part of the ePO database. This could lead to remote code execution on the ePO server with privilege escalation.Show less
1Simple Membership System Using Php And Ajax Project
1Simple Membership System Using Php And Ajax
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.
1South Gate Inn Online Reservation System Project
1South Gate Inn Online Reservation System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.
1Php Crud Without Refresh/reload Using Ajax And Datatables Tutorial Project
1Php Crud Without Refresh/reload Using Ajax And Datatables Tutorial
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_na...Show more
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.Show less
1Purchase Order Management System Project
1Purchase Order Management System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.
1Storage Unit Rental Management System Project
1Storage Unit Rental Management System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php.
1Oretnom23
1Online Learning System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.
1Wedevs
1Wp User Frontend
Jun 17, 2026
Jan 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanit...Show more
The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected Cross-Site ScriptingShow less
1Asgaros
1Asgaros Forum
Jun 17, 2026
Jan 24, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue
1Acf Extended
1Advanced Custom Fields\
Jun 17, 2026
Jan 24, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue