VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 46 of 1,041
  • CVE-2025-44033CriAug 29, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mappers/AddressMapper.java

  • CVE-2024-13979CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input…

  • CVE-2025-50972CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index.php. Three techniques have been demonstrated: error-based injection using a crafted FLOOR-based payload, time-based blind…

  • CVE-2025-55575CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with action=service_detail.

  • CVE-2025-56214CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.00

    phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.

  • CVE-2025-56212CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.00

    phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.

  • CVE-2025-51092CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.00

    The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in DataBase.php. The functions logIn() and signUp() build queries by directly concatenating user input and unvalidated table names without using prepared…

  • CVE-2024-53499CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.

  • CVE-2025-55444CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution.

  • CVE-2023-41530CriAug 7, 2025
    risk 0.64cvss 9.8epss 0.00

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

  • CVE-2023-41528CriAug 7, 2025
    risk 0.64cvss 9.8epss 0.00

    Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.

  • CVE-2023-41527CriAug 7, 2025
    risk 0.64cvss 9.8epss 0.00

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.

  • CVE-2023-41526CriAug 7, 2025
    risk 0.64cvss 9.8epss 0.00

    Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.

  • CVE-2023-41525CriAug 7, 2025
    risk 0.64cvss 9.8epss 0.00

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

  • CVE-2025-50341CriAug 4, 2025
    risk 0.64cvss 9.8epss 0.00

    A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false conditions, potentially leading to data exposure or further exploitation.

  • CVE-2025-41375CriAug 1, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.

  • CVE-2013-10033CriJul 31, 2025
    risk 0.64cvss —epss 0.02

    An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw allows attackers to inject arbitrary SQL queries into the dates[] POST parameter, enabling file write via INTO OUTFILE under specific environmental…

  • CVE-2025-40682CriJul 29, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint.

  • CVE-2025-6918CriJul 28, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection. This issue affects Virtual PBX Software: before 09.07.2025.

  • CVE-2025-4784CriJul 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection. This issue affects Tourtella: before 26.05.2025.