CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 395 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36394 | Hig | 0.49 | 7.6 | 0.01 | Aug 23, 2022 | Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. | ||
| CVE-2022-34968 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2022 | An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query. | ||
| CVE-2022-34067 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2022 | Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter. | ||
| CVE-2022-29709 | Hig | 0.49 | 7.5 | 0.01 | Jul 25, 2022 | CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters. | ||
| CVE-2022-32297 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2022 | Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function. | ||
| CVE-2022-32055 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2022 | Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=search/rentals. | ||
| CVE-2021-41460 | Hig | 0.49 | 7.5 | 0.07 | Jun 28, 2022 | ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information. | ||
| CVE-2022-33097 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job. | ||
| CVE-2022-33096 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index. | ||
| CVE-2022-33095 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. | ||
| CVE-2022-33094 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map. | ||
| CVE-2022-33093 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list. | ||
| CVE-2022-33092 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index. | ||
| CVE-2021-40956 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained. | ||
| CVE-2017-20029 | Hig | 0.49 | 7.3 | 0.21 | Jun 10, 2022 | A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the component Edit Subscription. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been… | ||
| CVE-2022-30496 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information. | ||
| CVE-2021-26633 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file. | ||
| CVE-2022-29721 | Hig | 0.49 | 7.5 | 0.01 | May 26, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. | ||
| CVE-2022-31489 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection. | ||
| CVE-2022-31488 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection. |
- risk 0.49cvss 7.6epss 0.01
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
- risk 0.49cvss 7.5epss 0.01
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.
- risk 0.49cvss 7.5epss 0.01
Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.
- risk 0.49cvss 7.5epss 0.01
CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.
- risk 0.49cvss 7.5epss 0.01
Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.
- risk 0.49cvss 7.5epss 0.01
Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=search/rentals.
- risk 0.49cvss 7.5epss 0.07
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.
- risk 0.49cvss 7.5epss 0.01
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.
- risk 0.49cvss 7.3epss 0.21
A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the component Edit Subscription. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been…
- risk 0.49cvss 7.5epss 0.01
SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.
- risk 0.49cvss 7.5epss 0.01
SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file.
- risk 0.49cvss 7.5epss 0.01
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.
- risk 0.49cvss 7.5epss 0.01
Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.
- risk 0.49cvss 7.5epss 0.01
Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.