← Back
CWE-89

20,883 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,883)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Roothub
1Roothub
Jun 17, 2026
May 6, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
-
-
Jun 17, 2026
May 6, 2024
N/A· v4
8.5 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.
-
-
Jun 17, 2026
May 6, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the my_index parameter.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in index.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the name parameter.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in /model/get_classroom.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the friend_index parameter.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
8.3 HIGH· v3
N/A· v2
A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.
1Campcodes
1Complete Web Based School Management System
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.
1Hsclabs
1Mailinspector
Jun 17, 2026
May 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspe...Show more
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthe...Show more
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
May 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unaut...Show more
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth fieldShow less
1Ibm
1Cognos Controller
Jun 17, 2026
May 3, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in...Show more
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 196643.Show less
1Kliqqi
1Kliqqi Cms
Jun 17, 2026
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Kliqqi-CMS 2.0.2 is vulnerable to SQL Injection in load_data.php via the userid parameter.
1Ibm
1Cognos Controller
Jun 17, 2026
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in...Show more
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 262183.Show less
-
-
Jun 17, 2026
May 3, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
Hengan Weighing Management Information Query Platform 2019-2021 53.25 was discovered to contain a SQL injection vulnerability via the tuser_Number parameter at search_user.aspx.
-
-
Jun 17, 2026
May 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in Gescen on the centrosdigitales.net platform. This vulnerability allows an attacker to send a specially crafted SQL query to the pass parameter and retrieve all the data stored in the databa...Show more
SQL injection vulnerability in Gescen on the centrosdigitales.net platform. This vulnerability allows an attacker to send a specially crafted SQL query to the pass parameter and retrieve all the data stored in the database.Show less