VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 43 of 1,041
  • CVE-2025-60736CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

  • CVE-2025-65358CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

  • CVE-2025-41013CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

  • CVE-2025-51683CriDec 1, 2025
    risk 0.64cvss 9.8epss 0.02

    A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .

  • CVE-2025-65236CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.

  • CVE-2025-65235CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function.

  • CVE-2025-52410CriNov 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The `myds` GET parameter is not adequately sanitized before being used in SQL queries.

  • CVE-2025-10437CriNov 19, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119.

  • CVE-2025-63694CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.

  • CVE-2025-41348CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete databases by sendng a POST request using the parameters 'val1' and 'cont in '/WinplusPortal/ws/sWinplus.svc/json/getacumper_post'.

  • CVE-2024-44659CriNov 17, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

  • CVE-2025-56385CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before being incorporated into a SQL query. Successful…

  • CVE-2025-64280CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field.

  • CVE-2025-8324CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.02

    Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.

  • CVE-2025-52425CriNov 7, 2025
    risk 0.64cvss 9.8epss 0.00

    An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QuMagie 2.7.0 and later

  • CVE-2022-50593CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.01

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the…

  • CVE-2022-50591CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.01

    Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the…

  • CVE-2022-50589CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.

  • CVE-2025-55343CriNov 5, 2025
    risk 0.64cvss 9.9epss 0.01

    Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista.php radi_temp, Administracion/listas/formArea_ajax.php codDepe,…

  • CVE-2025-12463CriNov 3, 2025
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.