VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (12,807)

page 388 of 641
  • CVE-2025-59369MedNov 25, 2025
    risk 0.38cvss epss 0.00

    A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary SQL queries, leading to unauthorized data access. Refer to the 'Security Update for ASUS Router Firmware' section on…

  • CVE-2025-27892MedApr 15, 2025
    risk 0.38cvss 6.8epss 0.12

    Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

  • CVE-2024-57178MedFeb 10, 2025
    risk 0.38cvss 5.9epss 0.00

    An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be able the user data or…

  • CVE-2024-28145MedDec 12, 2024
    risk 0.38cvss 5.9epss 0.01

    An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter…

  • CVE-2022-23169MedJun 13, 2022
    risk 0.38cvss 5.9epss 0.00

    attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.

  • CVE-2022-23168MedJun 13, 2022
    risk 0.38cvss 5.9epss 0.00

    The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'--

  • CVE-2022-1358MedMay 17, 2022
    risk 0.38cvss 5.9epss 0.01

    The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.

  • CVE-2022-0507MedMar 10, 2022
    risk 0.38cvss 5.8epss 0.01

    Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.

  • CVE-2021-37808MedOct 27, 2021
    risk 0.38cvss 5.9epss 0.02

    SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind…

  • CVE-2021-37806MedOct 27, 2021
    risk 0.38cvss 5.9epss 0.02

    An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used…

  • CVE-2021-25482MedOct 6, 2021
    risk 0.38cvss 5.9epss 0.00

    SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.

  • CVE-2020-26248MedDec 3, 2020
    risk 0.38cvss 6.8epss 0.12

    In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.

  • CVE-2020-5725MedMar 30, 2020
    risk 0.38cvss 5.9epss 0.02

    The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.

  • CVE-2018-15918MedSep 5, 2018
    risk 0.38cvss 5.4epss 0.03

    An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.

  • CVE-2026-22596MedJan 10, 2026
    risk 0.37cvss 6.7epss 0.00

    Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute arbitrary SQL. This issue has…

  • CVE-2024-8679MedDec 7, 2024
    risk 0.37cvss 6.8epss 0.00

    The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied…

  • CVE-2023-5591MedOct 16, 2023
    risk 0.37cvss 6.5epss 0.22

    SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.

  • CVE-2023-39524MedAug 7, 2023
    risk 0.37cvss 6.7epss 0.01

    PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, SQL injection possible in the product search field, in BO's product page. Version 8.1.1 contains a patch for this issue. There are no known workarounds.

  • CVE-2019-3792MedApr 1, 2019
    risk 0.37cvss 6.8epss 0.01

    Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.

  • CVE-2026-40830MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php files UpdateParam function due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values…