← Back
CWE-89

20,852 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,852)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lopalopa
1E Learning Management System
Jun 17, 2026
Nov 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.
1Lopalopa
1E Learning Management System
Jun 17, 2026
Nov 14, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
1Mayurik
1Best Employee Management System
Jun 17, 2026
Nov 14, 2024
5.1 MEDIUM· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /admin/edit_role.php. The manipulation of the argument id leads...Show more
A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /admin/edit_role.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Mayurik
1Best Employee Management System
Jun 17, 2026
Nov 14, 2024
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php....Show more
A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/fetch_product_details.php. The manipulation of the argument barcode leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Funnelkit
1Funnelkit Automations
Jun 17, 2026
Nov 14, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL s...Show more
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacksShow less
-
-
Jun 17, 2026
Nov 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The login form of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.283.4) at /Apps/TOPqw/Login.aspx is vulnerable to SQL injection. The vulnerability exists in the POST parameter txtUsername, which allows for...Show more
The login form of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.283.4) at /Apps/TOPqw/Login.aspx is vulnerable to SQL injection. The vulnerability exists in the POST parameter txtUsername, which allows for manipulation of SQL queries.Show less
-
-
Jun 17, 2026
Nov 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipul...Show more
The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipulation of SQL queries.Show less
-
-
Jun 17, 2026
Nov 13, 2024
8.6 HIGH· v4
8.0 HIGH· v3
N/A· v2
Improper neutralization of special elements used in an SQL command ('SQL Injection') in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of pri...Show more
Improper neutralization of special elements used in an SQL command ('SQL Injection') in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.Show less
1Oretnom23
1Computer Laboratory Management System
Jun 17, 2026
Nov 13, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
1Angeljudesuarez
1Construction Management System
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
1Angeljudesuarez
1Construction Management System
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.
1Nikoarroyocuraza
1Online Furniture Shopping Project
Jun 17, 2026
Nov 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 13, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.