CWE-89
20,774 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,774)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Chameleon Css Project 1Chameleon Css Jun 17, 2026 Nov 8, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of...Show more |
The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before using them in a SQL statement, leading to a SQL injection when adding a...Show more |
The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions av...Show more |
Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries. |
1Kaysongroup 1Php Event Calendar Jun 17, 2026 Nov 8, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversa...Show more |
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an a...Show more |
1Phpjabbers 1Fundraising Script Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function. |
1Phpjabbers 1Fundraising Script Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function. |
1Phpjabbers 1Fundraising Script Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function. |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web s...Show more |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and i...Show more |
1Online Event Booking And Reservation System Project 1Online Event Booking And Reservation System Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query perfor...Show more |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Nov 5, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cas...Show more |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication. |
1Simple Cashiering System Project 1Simple Cashiering System Jun 17, 2026 Nov 3, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in act...Show more |
1Oretnom23 1Simple Subscription Website Jun 17, 2026 Nov 3, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. |
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information. |
ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter. |
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php. |
1Customer Relationship Management System Project 1Customer Relationship Management System Jun 17, 2026 Nov 3, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php. |