← Back
CWE-89

20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,763)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sir
1Gnuboard
Jun 17, 2026
Jun 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
1Txjia
1Imcat
Jun 17, 2026
Jun 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
1Accellion
1Kiteworks
Jun 17, 2026
Jun 23, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive i...Show more
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.Show less
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jul 9, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
1Ayecode
1Location Manager
Jun 17, 2026
Jun 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to una...Show more
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.Show less
1White Shark Systems Project
1White Shark Systems
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerabili...Show more
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.Show less
1White Shark Systems Project
1White Shark Systems
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can...Show more
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.Show less
1White Shark Systems Project
1White Shark Systems
Jun 17, 2026
Jun 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain...Show more
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain database sensitive information.Show less
1Primion Digitek
1Secure 8
Jun 17, 2026
Jun 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and admini...Show more
Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and administrator accounts stored in the database.Show less
1Octopus
1Server
Jun 17, 2026
Jun 17, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerabil...Show more
Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.Show less