← Back
CWE-89

20,768 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,768)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Youphptube
1Youphptube
Jul 9, 2026
Nov 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as applicatio...Show more
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.Show less
1Apache
1Dolphinscheduler
Jun 17, 2026
Nov 1, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
1Yonyou
1Turbocrm
Jun 17, 2026
Oct 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information.
1Pharmacy Point Of Sale System Project
1Pharmacy Point Of Sale System
Jun 17, 2026
Oct 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.
1E Negosyo System Project
1E Negosyo System
Jun 17, 2026
Oct 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.
1Dhis2
1Dhis 2
Jun 17, 2026
Oct 29, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows authenticated remote attackers to execu...Show more
DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows authenticated remote attackers to execute arbitrary SQL commands via unspecified vectors. This vulnerability affects the `/api/trackedEntityInstances` and `/api/trackedEntityInstances/query` API endpoints in all DHIS2 versions 2.34, 2.35, and 2.36. It also affects versions 2.32 and 2.33 which have reached _end of support_ - exceptional security updates have been added to the latest *end of support* builds for these versions. Versions 2.31 and older are unaffected. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user - the vulnerability requires a conscious attack to be exploited. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance. There are no known exploits of the security vulnerabilities addressed by these patch releases. Security patches are available in DHIS2 versions 2.32-EOS, 2.33-EOS, 2.34.7, 2.35.7, and 2.36.4. There is no straightforward known workaround for DHIS2 instances using the Tracker functionality other than upgrading the affected DHIS2 server to one of the patches in which this vulnerability has been fixed. For implementations which do NOT use Tracker functionality, it may be possible to block all network access to POST to the `/api/trackedEntityInstances`, and `/api/trackedEntityInstances/query` endpoints as a temporary workaround while waiting to upgrade.Show less
1Cszcms
1Csz Cms
Jun 17, 2026
Oct 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
1Phpgurukul
1News Portal
Jun 17, 2026
Oct 27, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds del...Show more
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.Show less
1Phpgurukul
1Online Shopping Portal
Jun 17, 2026
Oct 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exi...Show more
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.Show less
1Phpgurukul
1Vehicle Parking Management System
Jun 17, 2026
Oct 27, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) fu...Show more
An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used on the (1) editid , (2) viewid, and (3) catename parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.Show less
1Online Covid Vaccination Scheduler System Project
1Online Covid Vaccination Scheduler System
Jun 17, 2026
Oct 27, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .
2Razormist
Sourcecodester
2Complaint Management System
Complaint Management System
Jun 17, 2026
Oct 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.
1Online Student Admission System Project
1Online Student Admission System
Jun 17, 2026
Oct 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.
1Mangboard
1Mang Board
Jun 17, 2026
Oct 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a rem...Show more
A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user information.Show less
1Wpchill
1Check & Log Email
Jun 17, 2026
Oct 25, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues
1Permalink Manager Lite Project
1Permalink Manager Lite
Jun 17, 2026
Oct 25, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection
1Game Server Status Project
1Game Server Status
Jun 17, 2026
Oct 25, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it in SQL statement, leading to an Authenticated SQL Injection in an admin page
1Bqe
1Billquick Web Suite
Jun 17, 2026
Oct 22, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for examp...Show more
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.Show less
1Cct95
1Chichen Tech Cms
Jun 17, 2026
Oct 22, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters.
1Macs Cms Project
1Macs Cms
Jun 17, 2026
Oct 22, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules.