CWE-89
20,642 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,642)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply crafted input that is executed as part...Show more |
SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve data...Show more |
WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<ema...Show more |
EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.20260113, specifically in the `Nextmatch` filt...Show more |
The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'fields' parameter in all versions up to, and including, 1.1.4 due to insufficient escaping on the use...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_ev...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameters 'Id_u...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter ‘Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_us...Show more |
1Quatuor 1Evaluacion De Desempeno Jun 17, 2026 Jan 27, 2026 9.3 CRITICAL· v4 7.5 HIGH· v3 N/A· v2 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'txAny...Show more |
1Fabian 1Mobile Shop Management System Jun 17, 2026 Jan 27, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter. |
1Fabian 1Mobile Shop Management System Jun 17, 2026 Jan 27, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter. |
Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q' search parameter. Attackers can inject malicious SQL code in the searc...Show more |