VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 316 of 1,043
  • CVE-2026-30534HigMar 27, 2026
    risk 0.54cvss 8.3epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.

  • CVE-2025-55262HigMar 26, 2026
    risk 0.54cvss 8.3epss 0.00

    HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database.

  • CVE-2026-2751HigFeb 27, 2026
    risk 0.54cvss 8.3epss 0.01

    Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8,…

  • CVE-2026-2247HigFeb 17, 2026
    risk 0.54cvss —epss 0.00

    SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL generated after downloading the student's report card in the ‘Day-to-day’…

  • CVE-2025-52472CriOct 6, 2025
    risk 0.54cvss —epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0, the REST search URL is vulnerable to HQL injection via the `orderField` parameter. The…

  • CVE-2025-10184HigSep 23, 2025
    risk 0.54cvss —epss 0.04

    The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to…

  • CVE-2025-50983HigAug 27, 2025
    risk 0.54cvss 8.3epss 0.00

    SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4.15.2787. The endpoint fails to properly sanitize user-supplied input, allowing attackers to inject and execute arbitrary SQL commands against the backend…

  • CVE-2025-40985HigJul 16, 2025
    risk 0.54cvss —epss 0.00

    SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an attacker to exfiltrate some data from the database via the ‘login’ parameter in the endpoint ‘/scatevision_web/index.php/loginForm’.

  • CVE-2025-41444HigJun 9, 2025
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.

  • CVE-2025-36528HigJun 9, 2025
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.

  • CVE-2025-27709HigJun 9, 2025
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.

  • CVE-2025-41407HigMay 23, 2025
    risk 0.54cvss 8.3epss 0.01

    Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.

  • CVE-2025-41403HigMay 22, 2025
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.

  • CVE-2025-3836HigMay 22, 2025
    risk 0.54cvss 8.3epss 0.06

    Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.

  • CVE-2025-47785HigMay 15, 2025
    risk 0.54cvss 8.3epss 0.01

    Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary registered users, this…

  • CVE-2025-25206HigFeb 14, 2025
    risk 0.54cvss 8.3epss 0.00

    eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to…

  • CVE-2025-25181MedKEVFeb 3, 2025
    risk 0.54cvss 5.8epss 0.56

    A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.

  • CVE-2024-9134HigJan 10, 2025
    risk 0.54cvss 8.3epss 0.01

    Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.

  • CVE-2024-49574HigNov 18, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.

  • CVE-2024-9459HigNov 5, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.