← Back
CWE-89

20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,759)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Bus Booking System Project
1Online Bus Booking System
Jun 17, 2026
Dec 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privil...Show more
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.Show less
1Prestashop
1Productcomments
Jun 17, 2026
Dec 3, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
1Processmaker
1Processmaker
Jun 17, 2026
Dec 3, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An att...Show more
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.Show less
1Admerc
1Gym Management System
Jun 17, 2026
Dec 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.
1Car Rental Management System Project
1Car Rental Management System
Jun 17, 2026
Dec 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.
1Point Of Sales In Php/pdo Project
1Point Of Sales In Php/pdo
Jun 17, 2026
Dec 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.
1Multi Restaurant Table Reservation System Project
1Multi Restaurant Table Reservation System
Jun 17, 2026
Dec 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input i...Show more
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.Show less
1Online Doctor Appointment Booking System Php And Mysql Project
1Online Doctor Appointment Booking System Php And Mysql
Jun 17, 2026
Dec 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
1Bloodx Project
1Bloodx
Jun 17, 2026
Dec 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
1Victor Cms Project
1Victor Cms
Jun 17, 2026
Dec 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
4Debian
HibernateOracle+1 more
5Communications Cloud Native Core Console
Debian LinuxHibernate Orm+2 more
Jun 17, 2026
Dec 2, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments...Show more
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.Show less
1Zte
1Zxv10 W908 Firmware
Jun 17, 2026
Dec 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can...Show more
A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.Show less
1Synology
1Safeaccess
Jun 17, 2026
Nov 30, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
1Br Automation
1Industrial Automation Aprol
Jun 17, 2026
Nov 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.
1Karenderia Multiple Restaurant System Project
1Karenderia Multiple Restaurant System
Jun 17, 2026
Nov 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifyi...Show more
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.Show less
1Vmware
1Sd Wan Orchestrator
Jun 17, 2026
Nov 24, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WA...Show more
VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WAN Orchestrator user may inject code into SQL queries which may lead to information disclosure.Show less
1Vmware
1Sd Wan Orchestrator
Jun 17, 2026
Nov 24, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call...Show more
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call using specially crafted SQL queries which may lead to unauthorized data access.Show less
1Newsscriptphp
1News Script Php Pro
Jun 17, 2026
Nov 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
1Microfocus
1Identity Manager
Jun 17, 2026
Nov 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Nov 19, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versio...Show more
In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.Show less