VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 49 of 1,041
  • CVE-2025-40665CriMay 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in /GIMWeb/PC/frmCorrectivosList.aspx.

  • CVE-2024-51101CriMay 23, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.

  • CVE-2024-6809CriMay 15, 2025
    risk 0.64cvss 9.8epss 0.01

    The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2024-6159CriMay 15, 2025
    risk 0.64cvss 9.8epss 0.03

    The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2025-46052CriMay 15, 2025
    risk 0.64cvss 9.8epss 0.01

    An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command and extract sensitive data by injecting a crafted payload into the DEL form field in a POST request to /StockCounts.php

  • CVE-2025-28056CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.

  • CVE-2025-44831CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

  • CVE-2025-26390CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and…

  • CVE-2023-49641CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.00

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2025-44830CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.00

    EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.

  • CVE-2025-4559CriMay 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2025-46192CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.00

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.

  • CVE-2025-46190CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.00

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.

  • CVE-2025-46189CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.

  • CVE-2025-46188CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.

  • CVE-2025-45885CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.

  • CVE-2025-0668CriMay 7, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: before 1.4.5.

  • CVE-2025-44073CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.

  • CVE-2025-40624CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability…

  • CVE-2025-40623CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability…