CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Bus Booking System Project 1Online Bus Booking System Jun 17, 2026 Dec 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privil...Show more |
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module. |
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An att...Show more |
1Admerc 1Gym Management System Jun 17, 2026 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable. |
1Car Rental Management System Project 1Car Rental Management System Jun 17, 2026 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php. |
1Point Of Sales In Php/pdo Project 1Point Of Sales In Php/pdo Jun 17, 2026 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php. |
1Multi Restaurant Table Reservation System Project 1Multi Restaurant Table Reservation System Jun 17, 2026 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input i...Show more |
1Online Doctor Appointment Booking System Php And Mysql Project 1Online Doctor Appointment Booking System Php And Mysql Jun 17, 2026 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php. |
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication. |
1Victor Cms Project 1Victor Cms Jun 17, 2026 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. |
4Debian HibernateOracle+1 more5Communications Cloud Native Core Console Debian LinuxHibernate Orm+2 moreJun 17, 2026 Dec 2, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments...Show more |
A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can...Show more |
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter. |
1Br Automation 1Industrial Automation Aprol Jun 17, 2026 Nov 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006. |
1Karenderia Multiple Restaurant System Project 1Karenderia Multiple Restaurant System Jun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifyi...Show more |
VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WA...Show more |
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call...Show more |
1Newsscriptphp 1News Script Php Pro Jun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action. |
1Microfocus 1Identity Manager Jun 17, 2026 Nov 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1. |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Nov 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versio...Show more |