CWE-89
20,923 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,923)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The manipulation of the argument key leads t...Show more |
A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown code of the file /Maintain/sprog_upstatus.php. The manipulation of the argument id leads to sql injecti...Show more |
1Walterjnr1 1Employee Management System Jun 17, 2026 Mar 21, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php. |
Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result in access to data which the user doesn't have permission to access. Ve...Show more |
SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people. |
SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php. |
A vulnerability was found in Folio Spring Module Core up to 1.1.5. It has been rated as critical. Affected by this issue is the function dropSchema of the file tenant/src/main/java/org/folio/spring/tenant/hibernate/Hiber...Show more |
1Campcodes 1Complete Online Dj Booking System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability has been found in Campcodes Complete Online DJ Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/booking-bwdates-reports-details....Show more |
SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component. |
1Prestashop 1Abandoned Cart Reminder Pro Jun 17, 2026 Mar 20, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/applicants/index.php. The manipulation of the argument id lead...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/applicants/controller.php. The manipulation of the a...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/category/controller.php. The manipulation...Show more |
The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of suffi...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in Campcodes Online Job Finder System 1.0. Affected is an unknown function of the file /admin/company/controller.php. The manipulation of the argument id leads...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in Campcodes Online Job Finder System 1.0. This issue affects some unknown processing of the file /admin/company/index.php. The manipulation of the argume...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in Campcodes Online Job Finder System 1.0. This vulnerability affects unknown code of the file /admin/employee/index.php. The manipulation of the argument id leads to sql...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in Campcodes Online Job Finder System 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument user_email leads to sql injecti...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/user/controller.php. The manipulation of the arg...Show more |
1Campcodes 1Online Job Finder System Jun 17, 2026 Mar 20, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability was found in Campcodes Online Job Finder System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/user/index.php. The manipulation of the...Show more |