CWE-89
20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,927)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Boyiddha 1Automated Mess Management System Jun 17, 2026 Mar 8, 2024 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component Login Page. The manipulation o...Show more |
1Prestatoolkit 1Make An Offer/offer Your Price Jun 17, 2026 Mar 8, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` . |
In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions. |
1Cleanpresta 1Cd Custom Fields 4 Orders Jun 17, 2026 Mar 8, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions. |
1Keerti1924 1Online Bookstore Website Jun 17, 2026 Mar 8, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in keerti1924 Online-Book-Store-Website 1.0. This vulnerability affects unknown code of the file /home.php of the component HTTP POST Request Handler. The manipulation of...Show more |
1Keerti1924 1Online Bookstore Website Jun 17, 2026 Mar 8, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in keerti1924 Online-Book-Store-Website 1.0. This affects an unknown part of the file /shop.php of the component HTTP POST Request Handler. The manipulation of the ar...Show more |
1Keerti1924 1Online Bookstore Website Jun 17, 2026 Mar 7, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argumen...Show more |
1Keerti1924 1Php Mysql User Signup Login System Jun 17, 2026 Mar 7, 2024 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argume...Show more |
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1. |
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer." |
1Oretnom23 1Lost And Found Information System Jun 17, 2026 Mar 7, 2024 N/A· v4 8.4 HIGH· v3 N/A· v2 Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Mar 7, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Mar 7, 2024 N/A· v4 2.7 LOW· v3 N/A· v2 Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php. |
1Phpgurukul 1Hospital Management System Jun 17, 2026 Mar 7, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php. |
Chat functionality in Schoolbox application before
version 23.1.3 is vulnerable to blind SQL Injection enabling the
authenticated attackers to read, modify, and delete database records. |
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter. |
1Pratham Jaiswal 1Hotel Booking Management System Jun 17, 2026 Mar 7, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php. |
1Pratham Jaiswal 1Hotel Booking Management System Jun 17, 2026 Mar 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php. |
3Jackc Pgproto3 ProjectPgx Project4Pgproto3 Pgproto3Pgx+1 moreJun 17, 2026 Mar 6, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one...Show more |
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value mus...Show more |