← Back
CWE-89

20,781 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,781)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Banking System Project
1Online Banking System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.
1Online Leave Management System Project
1Online Leave Management System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.
1Simple College Website Project
1Simple College Website
Jun 17, 2026
Jan 21, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.
1Oretnom23
1Budget And Expense Tracker System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
1Oretnom23
1Employee And Visitor Gate Pass Logging System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
1Online Railway Reservation System Project
1Online Railway Reservation System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.
1Projectworlds
1Online Examination System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.
1Online Resort Management System Project
1Online Resort Management System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.
1Oretnom23
1Simple Music Cloud Community System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
1Courier Management System Project
1Courier Management System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.
1Mingsoft
1Mcms
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
1Computer And Mobile Repair Shop Management System Project
1Computer And Mobile Repair Shop Management System
Jun 17, 2026
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app.
1Covid 19 Testing Management System Project
1Covid 19 Testing Management System
Jun 17, 2026
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.
1Sourcecodester Logistic Hub Parcel's Management System Project
1Sourcecodester Logistic Hub Parcel's Management System
Jun 17, 2026
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php.
1Code Projects
1Pharmacy Management
Jun 17, 2026
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.
1Sourcecodester Online Reviewer System Project
1Sourcecodester Online Reviewer System
Jun 17, 2026
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.
1Phpipam
1Phpipam
Jun 17, 2026
Jan 19, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
1Taogogo
1Taocms
Jun 17, 2026
Jan 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php.
5Apache
BroadcomNetapp+2 more
28Advanced Supply Chain Planning
Brocade SannavBusiness Intelligence+25 more
Jun 17, 2026
Jan 18, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be includ...Show more
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.Show less
1Softvibe
1Saraban
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.