CWE-89
20,665 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,665)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Itsourcecode 1Web Based Internet Laboratory Management System Jun 17, 2026 Nov 17, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulation can lead to sql injection. The attack...Show more |
1Itsourcecode 1Web Based Internet Laboratory Management System Jun 17, 2026 Nov 17, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation results in sql injectio...Show more |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. |
1Phpgurukul 1Complaint Management System Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php. |
1Phpgurukul 1Complaint Management System Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php. |
1Itsourcecode 1Web Based Internet Laboratory Management System Jun 17, 2026 Nov 17, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impacted element is an unknown function of the file /course/controller.php. Such manipulation leads to s...Show more |
1Phpgurukul 1Complaint Management System Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php. |
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php. |
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php. |
phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in the main configuration update functionality of phpMyFAQ allows a privileged user with 'Configuratio...Show more |
An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via crafted input. The API is not enabled by default, and a valid API t...Show more |
1Campcodes 1Supplier Management System Jun 17, 2026 Nov 17, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the argument ID results in sql injection. The...Show more |
1Fabian 1Simple Food Ordering System Jun 17, 2026 Nov 17, 2025 2.1 LOW· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /saveorder.php. Such manipulation of the argument ID leads to sql injectio...Show more |
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php. |
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. |
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. |