CWE-89
20,895 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,895)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Janobe 1Aplaya Beach Resort Online Reservation System Jun 17, 2026 Apr 5, 2024 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this issue is some unknown functionality of the file admin/mod_room/index...Show more |
1Janobe 1Aplaya Beach Resort Online Reservation System Jun 17, 2026 Apr 5, 2024 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability classified as critical was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/login.php. The manipulati...Show more |
1Janobe 1Aplaya Beach Resort Online Reservation System Jun 17, 2026 Apr 5, 2024 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability classified as critical has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected is an unknown function of the file booking/index.php. The manipulation of the argument l...Show more |
1Sanchitkmr 1Airline Ticket Reservation System Jun 17, 2026 Apr 5, 2024 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file activate_jet_details_form_handler.php. The manipula...Show more |
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user suppli...Show more |
InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthoriz...Show more |
1Oretnom23 1Computer Laboratory Management System Jun 17, 2026 Apr 4, 2024 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/view_categor...Show more |
1Oretnom23 1Computer Laboratory Management System Jun 17, 2026 Apr 4, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file classes/user.php. The manipulation of the argument id...Show more |
1Oretnom23 1Computer Laboratory Management System Jun 17, 2026 Apr 4, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php. The manipulation leads to sql i...Show more |
projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php. |
SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component. |
1Chatikobo 1Internship Portal Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/delete_activity.php. The manipulation of th...Show more |
1Chatikobo 1Internship Portal Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin/add_activity.php. The manipulation of the argument t...Show more |
1Chatikobo 1Internship Portal Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/edit_activity_query.php. The manipula...Show more |
1Chatikobo 1Internship Portal Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/edit_activity.php. The man...Show more |
1Chatikobo 1Internship Portal Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in SourceCodester Internship Portal Management System 1.0. Affected is an unknown function of the file admin/edit_admin_query.php. The manipulation of the argu...Show more |
1Chatikobo 1Internship Portal Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Internship Portal Management System 1.0. This issue affects some unknown processing of the file admin/edit_admin.php. The manipulation o...Show more |
1Chatikobo 1Internship Portal Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in SourceCodester Internship Portal Management System 1.0. This vulnerability affects unknown code of the file admin/add_admin.php. The manipulation of the argument name/u...Show more |
1Chatikobo 1Internship Portal Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in SourceCodester Internship Portal Management System 1.0. This affects an unknown part of the file admin/check_admin.php. The manipulation of the argument username/p...Show more |
1Oretnom23 1Computer Laboratory Management System Jun 17, 2026 Apr 3, 2024 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/?page=borrow/view_borrow. The...Show more |