← Back
CWE-89

20,774 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,774)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chameleon Css Project
1Chameleon Css
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of...Show more
The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL InjectionShow less
1Web Dorado
1Spidercatalog
Jun 17, 2026
Nov 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before using them in a SQL statement, leading to a SQL injection when adding a...Show more
The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before using them in a SQL statement, leading to a SQL injection when adding a categoryShow less
1Igexsolutions
1Wpschoolpress
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions av...Show more
The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.Show less
1Servicetonic
1Servicetonic
Jun 17, 2026
Nov 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.
1Kaysongroup
1Php Event Calendar
Jun 17, 2026
Nov 8, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversa...Show more
PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.Show less
1Hitachi
1Vantara Pentaho
Jun 17, 2026
Nov 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an a...Show more
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.Show less
1Phpjabbers
1Fundraising Script
Jun 17, 2026
Nov 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
1Phpjabbers
1Fundraising Script
Jun 17, 2026
Nov 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
1Phpjabbers
1Fundraising Script
Jun 17, 2026
Nov 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.
1Engineers Online Portal Project
1Engineers Online Portal
Jun 17, 2026
Nov 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web s...Show more
A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.Show less
1Engineers Online Portal Project
1Engineers Online Portal
Jun 17, 2026
Nov 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and i...Show more
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a remote code execution on the remote web server.Show less
1Online Event Booking And Reservation System Project
1Online Event Booking And Reservation System
Jun 17, 2026
Nov 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query perfor...Show more
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.Show less
1Engineers Online Portal Project
1Engineers Online Portal
Jun 17, 2026
Nov 5, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cas...Show more
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.Show less
1Engineers Online Portal Project
1Engineers Online Portal
Jun 17, 2026
Nov 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.
1Simple Cashiering System Project
1Simple Cashiering System
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in act...Show more
Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.Show less
1Oretnom23
1Simple Subscription Website
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
1Php Cms Project
1Php Cms
Jun 17, 2026
Nov 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.
1Ed01 Cms Project
1Ed01 Cms
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.
1Eyoucms
1Eyoucms
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.
1Customer Relationship Management System Project
1Customer Relationship Management System
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.