CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 132 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25505 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2022 | Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php. | ||
| CVE-2021-44088 | Cri | 0.64 | 9.8 | 0.03 | Mar 17, 2022 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters. | ||
| CVE-2022-26293 | Cri | 0.64 | 9.8 | 0.02 | Mar 16, 2022 | Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php. | ||
| CVE-2022-25494 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php. | ||
| CVE-2022-25492 | Cri | 0.64 | 9.8 | 0.02 | Mar 15, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php. | ||
| CVE-2022-25490 | Cri | 0.64 | 9.8 | 0.02 | Mar 15, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php. | ||
| CVE-2022-25488 | Cri | 0.64 | 9.8 | 0.07 | Mar 15, 2022 | Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php. | ||
| CVE-2022-0658 | Cri | 0.64 | 9.8 | 0.09 | Mar 14, 2022 | The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection | ||
| CVE-2021-25007 | Cri | 0.64 | 9.8 | 0.02 | Mar 14, 2022 | The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection | ||
| CVE-2022-24607 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. | ||
| CVE-2022-24606 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. | ||
| CVE-2022-24605 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. | ||
| CVE-2022-24604 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. | ||
| CVE-2022-24603 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. | ||
| CVE-2022-24602 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. | ||
| CVE-2022-24600 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements. | ||
| CVE-2022-26201 | Cri | 0.64 | 9.8 | 0.01 | Mar 4, 2022 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2022-25125 | Cri | 0.64 | 9.8 | 0.07 | Mar 3, 2022 | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. | ||
| CVE-2022-23899 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2022 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java. | ||
| CVE-2022-23898 | Cri | 0.64 | 9.8 | 0.08 | Mar 3, 2022 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. |
- risk 0.64cvss 9.8epss 0.01
Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php.
- risk 0.64cvss 9.8epss 0.03
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
- risk 0.64cvss 9.8epss 0.02
Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.
- risk 0.64cvss 9.8epss 0.01
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.
- risk 0.64cvss 9.8epss 0.02
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
- risk 0.64cvss 9.8epss 0.02
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
- risk 0.64cvss 9.8epss 0.07
Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.
- risk 0.64cvss 9.8epss 0.09
The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection
- risk 0.64cvss 9.8epss 0.02
The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
- risk 0.64cvss 9.8epss 0.01
Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.
- risk 0.64cvss 9.8epss 0.01
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.07
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
- risk 0.64cvss 9.8epss 0.01
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
- risk 0.64cvss 9.8epss 0.08
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.