← Back
CWE-89

20,778 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,778)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-si...Show more
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-site request forgery.Show less
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘username_filter’ parameter with the administrative account or through cross-s...Show more
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘username_filter’ parameter with the administrative account or through cross-site request forgery.Show less
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter with the administrative account or through cross-site...Show more
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter with the administrative account or through cross-site request forgery.Show less
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘surname_filter’ parameter with the administrative account or through cross-si...Show more
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘surname_filter’ parameter with the administrative account or through cross-site request forgery.Show less
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ord’ parameter. However, the high privilege super-administrator account needs...Show more
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ord’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site request forgery attack.Show less
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter. However, the high privilege super-administrator accou...Show more
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site request forgery attack.Show less
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP reque...Show more
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.Show less
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authentica...Show more
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.Show less
1Advantech
1R Seenet
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated...Show more
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.Show less
1Projectworlds
1Hospital Management System In Php
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.
1Projectworlds
1Hospital Management System In Php
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases...Show more
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.Show less
1Projectworlds
1Hospital Management System In Php
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
1Projectworlds
1Hospital Management System In Php
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
1Projectworlds
1Online Shopping System
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
1Projectworlds
1Online Book Store Project In Php
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.
1Anuko
1Time Tracker
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. SQL injection vulnerability exist in multiple files in Time Tracker version 1.19.33.5606 and prior due to not properly checking of...Show more
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. SQL injection vulnerability exist in multiple files in Time Tracker version 1.19.33.5606 and prior due to not properly checking of the "group" and "status" parameters in POST requests. Group parameter is posted along when navigating between organizational subgroups (groups.php file). Status parameter is used in multiple files to change a status of an entity such as making a project, task, or user inactive. This issue has been patched in version 1.19.33.5607. An upgrade is highly recommended. If an upgrade is not practical, introduce ttValidStatus function as in the latest version and start using it user input check blocks wherever status field is used. For groups.php fix, introduce ttValidInteger function as in the latest version and use it in the access check block in the file.Show less
1Dalmark
1Systeam Enterprise Resource Planning
Jun 17, 2026
Dec 21, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management,...Show more
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. The bi report module exposes direct SQL commands via POST data in order to select data for report generation. A malicious actor can use the bi report endpoint as a direct SQL prompt under the authenticated user.Show less
1Video Sharing Website Project
1Video Sharing Website
Jun 17, 2026
Dec 21, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that referenc...Show more
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.Show less
1Simple Cold Storage Management System Project
1Simple Cold Storage Managment System
Jun 17, 2026
Dec 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC fi...Show more
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed.Show less
1Oretnom23
1Simple Forum/discussion System
Jun 17, 2026
Dec 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all infor...Show more
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.Show less