CWE-89
20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,763)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. |
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php. |
Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive i...Show more |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jul 9, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to una...Show more |
1White Shark Systems Project 1White Shark Systems Jun 17, 2026 Jun 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerabili...Show more |
1White Shark Systems Project 1White Shark Systems Jun 17, 2026 Jun 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can...Show more |
1White Shark Systems Project 1White Shark Systems Jun 17, 2026 Jun 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain...Show more |
Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injection. An attacker could exploit this vulnerability in order to extract information of users and admini...Show more |
Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerabil...Show more |