← Back
CWE-89

20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,763)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 23, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPa...Show more
A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 23, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPa...Show more
A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database.Show less
1Mailtrain
1Mailtrain
Jun 17, 2026
Feb 19, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.
1Doctor Appointment System Project
1Doctor Appointment System
Jun 17, 2026
Feb 18, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.
1Janobe
1Baby Care System
Jun 17, 2026
Feb 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page.
1Online Book Store Project
1Online Book Store
Jun 17, 2026
Feb 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.
1Seat Reservation System Project
1Seat Reservation System
Jun 17, 2026
Feb 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.
1Hr Portal Project
1Hr Portal
Jun 17, 2026
Feb 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege.
1Changjia Property Management System Project
1Changjia Property Management System
Jun 17, 2026
Feb 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege.
1Sdg
1Pnpscada
Jul 9, 2026
Feb 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in...Show more
PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.Show less
1Mutare
1Voice
Jun 17, 2026
Feb 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. The web application suffers from SQL injection on Adminlog.asp, Archivemsgs.asp, Deletelog.asp, Eventlog.asp, and Evmlog.asp.
1E Learning System Project
1E Learning System
Jun 17, 2026
Feb 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell.
1Phpgurukul
1Teachers Record Management System
Jun 17, 2026
Feb 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak...Show more
Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.Show less
1Casap Automated Enrollment System Project
1Casap Automated Enrollment System
Jun 17, 2026
Feb 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login...Show more
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.Show less
1Library System Project
1Library System
Jun 17, 2026
Feb 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login as the admin user.
1Open Emr
1Openemr
Jun 17, 2026
Feb 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
1Open Emr
1Openemr
Jun 17, 2026
Feb 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in interface/reports/immunization_report.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
1Open Emr
1Openemr
Jun 17, 2026
Feb 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the searchFields p...Show more
A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the searchFields parameter.Show less
1Open Emr
1Openemr
Jun 17, 2026
Feb 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the schedule_facility parameter when restric...Show more
A SQL injection vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the schedule_facility parameter when restrict_user_facility=on is in global settings.Show less
1Centreon
1Centreon
Jun 17, 2026
Feb 15, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.