← Back
CWE-89

20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,763)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Naviwebs
1Navigatecms
Jun 17, 2026
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.
1Naviwebs
1Navigatecms
Jun 17, 2026
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.
1Naviwebs
1Navigatecms
Jun 17, 2026
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.
1Naviwebs
1Navigatecms
Jun 17, 2026
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend databas...Show more
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.Show less
1Woocommerce
1Woocommerce
Jun 17, 2026
Jul 26, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having...Show more
Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can exploit vulnerable endpoints of `/wp-json/wc/v3/webhooks`, `/wp-json/wc/v2/webhooks` and other webhook listing API. Read-only SQL queries can be executed using this exploit, while data will not be returned, by carefully crafting `search` parameter information can be disclosed using timing and related attacks. Version 3.3.6 is the earliest version of Woocommerce with a patch for this vulnerability. There are no known workarounds other than upgrading.Show less
1Automattic
1Woocommerce Blocks
Jun 17, 2026
Jul 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0...Show more
woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce Blocks feature plugin between version 2.5.0 and prior to version 2.5.16. Via a carefully crafted URL, an exploit can be executed against the `wc/store/products/collection-data?calculate_attribute_counts[][taxonomy]` endpoint that allows the execution of a read only sql query. There are patches for many versions of this package, starting with version 2.5.16. There are no known workarounds aside from upgrading.Show less
1Learning Management System Project
1Learning Management System
Jun 17, 2026
Jul 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.
1Travel Management System Project
1Travel Management System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php.
1Theme Park Ticketing System Project
1Theme Park Ticketing System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_user.php .
1E Commerce Website Project
1E Commerce Website
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php .
1Casap Automated Enrollment System Project
1Casap Automated Enrollment System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.
1Alumni Management System Project
1Alumni Management System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.
1Casap Automated Enrollment System Project
1Casap Automated Enrollment System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php.
1Sales And Inventory System Project
1Sales And Inventory System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to \ahira\admin\inventory.php.
1Water Billing System Project
1Water Billing System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php.
1Simple College Website Project
1Simple College Website
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.
1Fantastic Blog Cms Project
1Fantastic Blog Cms
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php.
1Casap Automated Enrollment System Project
1Casap Automated Enrollment System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.
1Casap Automated Enrollment System Project
1Casap Automated Enrollment System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.
1Phpgurukul
1Student Record System
Jun 17, 2026
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.