VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 219 of 1,043
  • CVE-2024-52874HigMay 22, 2025
    risk 0.58cvss 8.8epss 0.10

    In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.

  • CVE-2025-46337CriMay 1, 2025
    risk 0.58cvss 10.0epss 0.01

    ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a…

  • CVE-2024-8309CriOct 29, 2024
    risk 0.58cvss 9.8epss 0.14

    A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in…

  • CVE-2024-38814HigOct 16, 2024
    risk 0.58cvss 8.8epss 0.15

    An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated user with non-administrator privileges may be able to enter specially crafted SQL queries and perform unauthorized remote code execution on the HCX…

  • CVE-2024-35584HigOct 15, 2024
    risk 0.58cvss 8.8epss 0.06

    SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the…

  • CVE-2024-9379MedKEVOct 8, 2024
    risk 0.58cvss 6.5epss 0.44

    SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

  • CVE-2024-42417HigOct 3, 2024
    risk 0.58cvss 8.8epss 0.07

    Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.

  • CVE-2024-42561HigAug 20, 2024
    risk 0.58cvss 8.8epss 0.09

    Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.

  • CVE-2024-39309CriJul 1, 2024
    risk 0.58cvss 9.8epss 0.20

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection…

  • CVE-2024-6028CriJun 25, 2024
    risk 0.58cvss 9.8epss 0.12

    The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

  • CVE-2024-36412CriJun 10, 2024
    risk 0.58cvss 10.0epss 0.06

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-4295CriJun 5, 2024
    risk 0.58cvss 9.8epss 0.10

    The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2024-4443CriMay 22, 2024
    risk 0.58cvss 9.8epss 0.10

    The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter…

  • CVE-2024-32888CriMay 15, 2024
    risk 0.58cvss 10.0epss 0.01

    The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using…

  • CVE-2024-34032HigMay 3, 2024
    risk 0.58cvss 8.8epss 0.09

    Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

  • CVE-2024-25574HigApr 1, 2024
    risk 0.58cvss 8.8epss 0.09

    SQL injection vulnerability exists in GetDIAE_usListParameters.

  • CVE-2024-30491HigMar 29, 2024
    risk 0.58cvss 8.5epss 0.32

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

  • CVE-2024-28040HigMar 21, 2024
    risk 0.58cvss 8.8epss 0.08

    SQL injection vulnerability exists in GetDIAE_astListParameters.

  • CVE-2024-23975HigMar 21, 2024
    risk 0.58cvss 8.8epss 0.08

    SQL injection vulnerability exists in GetDIAE_slogListParameters.

  • CVE-2024-23494HigMar 21, 2024
    risk 0.58cvss 8.8epss 0.08

    SQL injection vulnerability exists in GetDIAE_unListParameters.