CWE-89
20,925 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,925)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of...Show more |
1Code Projects 1Scholars Tracking System Jun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update. |
1Code Projects 1Scholars Tracking System Jun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information. |
1Code Projects 1Scholars Tracking System Jun 17, 2026 Mar 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php. |
SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the informatio...Show more |
1Fortinet 1Forticlient Enterprise Management Server Jun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized c...Show more |
1Remyandrade 1Crud Without Page Reload/refresh Jun 17, 2026 Mar 12, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file add_user.php. The manipulation of the arg...Show more |
1Walterjnr1 1Employee Management System Jun 17, 2026 Mar 12, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php. |
The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins. |
Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php. |
1Codeastro 1Ecommerce Website Jun 17, 2026 Mar 9, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in CodeAstro Ecommerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file action.php of the component Search. The manipulation of the argumen...Show more |
1Codeastro 1Membership Management System Jun 17, 2026 Mar 9, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in CodeAstro Membership Management System 1.0. Affected is an unknown function of the file /add_members.php. The manipulation of the argument fullname leads to sql in...Show more |
1Oretnom23 1Online Mobile Store Management System Jun 17, 2026 Mar 9, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_category.php of the componen...Show more |
1Netentsec 1Application Security Gateway Jun 17, 2026 Mar 9, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /protocol/index.php. The manipulation of the argument IPAddr le...Show more |
1Netentsec 1Application Security Gateway Jun 17, 2026 Mar 9, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_resource_icon.php?action=delete. The...Show more |
PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to superuser when dynamic masking is enabled. PostgreSQL Anonymizer enables users to set security labels on...Show more |
A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerabi...Show more |
1Boyiddha 1Automated Mess Management System Jun 17, 2026 Mar 8, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in boyiddha Automated-Mess-Management-System 1.0. Affected is an unknown function of the file /member/view.php. The manipulation of the argument date leads to sql inj...Show more |
1Boyiddha 1Automated Mess Management System Jun 17, 2026 Mar 8, 2024 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation o...Show more |
1Prestatoolkit 1Make An Offer/offer Your Price Jun 17, 2026 Mar 8, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` . |