← Back
CWE-89

20,617 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
5Sql Server 2016
Sql Server 2017Sql Server 2019+2 more
Jun 17, 2026
Apr 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
1Fortinet
1Fortiddos F
Jun 17, 2026
Apr 14, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending cra...Show more
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requestsShow less
1Fortinet
1Forticlientems
Jun 17, 2026
Apr 14, 2026
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions ma...Show more
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requestsShow less
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manip...Show more
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manipulate SQL query logic and extract sensitive database information.Show less
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.
1Fortinet
4Fortianalyzer
Fortianalyzer CloudFortimanager+1 more
Aug 12, 2026
Apr 14, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, Fort...Show more
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2 through 7.6.3, FortiAnalyzer-BigData 7.6.0 through 7.6.1, FortiAnalyzer-BigData 7.4.0 through 7.4.5, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.4 may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC APIShow less
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/manage_pricing.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tenants/view_details.php.
-
-
Jun 17, 2026
Apr 14, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rents/manage_rent.php.