VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 215 of 1,043
  • CVE-2025-52390CriAug 1, 2025
    risk 0.59cvss 9.1epss 0.01

    Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in `FulltextSearch.class.php`. The application directly concatenates user-supplied input (`$search_word`) into SQL queries without…

  • CVE-2025-49853CriJun 24, 2025
    risk 0.59cvss 9.1epss 0.00

    ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.

  • CVE-2024-36465HigApr 2, 2025
    risk 0.59cvss 8.8epss 0.40

    A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.

  • CVE-2025-24799HigMar 18, 2025
    risk 0.59cvss 7.5epss 0.87

    GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.

  • CVE-2025-22699CriFeb 4, 2025
    risk 0.59cvss 9.0epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.2.

  • CVE-2024-57587CriJan 31, 2025
    risk 0.59cvss 9.1epss 0.01

    Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.

  • CVE-2024-55573CriJan 23, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.

  • CVE-2024-53923CriJan 23, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection in the form to upload media.

  • CVE-2024-55496CriDec 17, 2024
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.

  • CVE-2024-51164CriNov 15, 2024
    risk 0.59cvss 9.1epss 0.01

    Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

  • CVE-2024-51063CriOct 31, 2024
    risk 0.59cvss 9.1epss 0.01

    Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.

  • CVE-2024-51060CriOct 31, 2024
    risk 0.59cvss 9.1epss 0.00

    Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.

  • CVE-2024-7385CriSep 25, 2024
    risk 0.59cvss 9.1epss 0.01

    The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2024-43040CriSep 10, 2024
    risk 0.59cvss 9.1epss 0.00

    Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.

  • CVE-2024-42885CriSep 5, 2024
    risk 0.59cvss 9.1epss 0.01

    SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.

  • CVE-2024-33854CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-33853CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-33852CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-5975CriJul 30, 2024
    risk 0.59cvss 9.1epss 0.02

    The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2024-39907CriJul 18, 2024
    risk 0.59cvss 9.8epss 0.29

    1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls.…