CWE-89
20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,927)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Adaudit Plus Jun 17, 2026 Feb 2, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. |
1Zohocorp 1Manageengine Adaudit Plus Jun 17, 2026 Feb 2, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. |
facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file fm-...Show more |
1Sparxsystems 1Enterprise Architect Jun 17, 2026 Jan 31, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box.. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9. |
A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The manipulat...Show more |
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.
|
1Remyandrade 1School Task Manager Jun 17, 2026 Jan 29, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter. |
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.' |
1Remyandrade 1Login System With Email Verification Jun 17, 2026 Jan 29, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter. |
1Employee Management System Project 1Employee Management System Jun 17, 2026 Jan 29, 2024 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Admin/login.php. The manipulation of the argume...Show more |
1Razormist 1Employee Management System Jun 17, 2026 Jan 29, 2024 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. The manipulation of the argument txtfullname l...Show more |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delhivery Delhivery Logistics Courier.This issue affects Delhivery Logistics Courier: from n/a through 1.0.107. |
1Wpovernight 1Woocommerce Pdf Invoices& Packing Slips Jun 17, 2026 Jan 27, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects PDF Invoices & Packing Slips for WooComme...Show more |
A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the argument sort leads to sql injection....Show more |
1Tongda2000 1Office Anywhere Jun 17, 2026 Jan 26, 2024 N/A· v4 9.8 CRITICAL· v3 5.2 MEDIUM· v2 A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.9. This affects an unknown part of the file /general/email/inbox/delete_webmail.php. The manipulation of the argument WEBBODY_ID_STR...Show more |
A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It...Show more |
1Mayurik 1Online Tours &travels Management System Jun 17, 2026 Jan 25, 2024 N/A· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec of the file payment.php. The manipulation of the argument id l...Show more |
1Mayurik 1Online Tours & Travels Management System Jun 17, 2026 Jan 25, 2024 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare of the file admin/pay.php. The manipulation of t...Show more |
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter `select...Show more |