CWE-89
20,876 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,876)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml . |
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml. |
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml. |
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml. |
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 8.6 HIGH· v3 N/A· v2 A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the month parameter. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id paramete...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A SQL injection vulnerability in /model/update_grade.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the admission_fee parameter. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the month parameter. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the my_index parameter. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 A SQL injection vulnerability in /model/update_subject_routing.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter. |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter. |
1Unlimited Elements 1Unlimited Elements For Elementor Jun 17, 2026 May 23, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insuff...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 5.3 MEDIUM· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/unread_msg.php. The manipulation of the argu...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 5.3 MEDIUM· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/timetable_update_form.php. The manipulatio...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 5.3 MEDIUM· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/timetable_insert_form.php. The manipulation of the...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 23, 2024 5.3 MEDIUM· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /view/timetable_grade_wise....Show more |