← Back
CWE-89

20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,927)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
1Unity Operating Environment
Jun 17, 2026
Feb 12, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information.
1Storeapps
1Smart Manager
Jun 17, 2026
Feb 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
1Qanything
1Qanything
Jun 17, 2026
Feb 11, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.
1Getawesomesupport
1Awesome Support
Jun 17, 2026
Feb 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due...Show more
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.Show less
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
1Code Projects
1Simple School Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."
1Code Projects
1Cinema Seat Reservation System
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."
1Remyandrade
1Event Student Attendance System
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.
1Oduyo
1Online Collection
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection. This issue affects Online Collection: before v.1.0...Show more
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection. This issue affects Online Collection: before v.1.0.2.Show less
1Code Projects
1Simple School Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."
1Code Projects
1Simple School Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.
1Code Projects
1Simple School Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.
1Code Projects
1Simple School Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
1Code Projects
1Simple School Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.
1Code Projects
1Simple School Management System
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
1Boostmyshop
1Boostmyshop
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, r...Show more
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.Show less
1Prestamonster
1Multi Accessories Pro
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive informati...Show more
SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts().Show less