CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 51 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-40073 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4. | ||
| CVE-2024-40072 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1. | ||
| CVE-2025-28100 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2025 | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter. | ||
| CVE-2025-25226 | Cri | 0.64 | 9.8 | 0.00 | Apr 8, 2025 | Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the… | ||
| CVE-2025-29647 | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2025 | SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php. | ||
| CVE-2024-22611 | Cri | 0.64 | 9.8 | 0.06 | Apr 3, 2025 | OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php. | ||
| CVE-2025-29369 | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2025 | Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1. | ||
| CVE-2025-22930 | — | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2025 | OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php. | |
| CVE-2025-22929 | — | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2025 | OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php. | |
| CVE-2025-22928 | — | Cri | 0.64 | 9.8 | 0.00 | Apr 3, 2025 | OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php. | |
| CVE-2025-3096 | Cri | 0.64 | — | 0.01 | Apr 1, 2025 | Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page. | ||
| CVE-2025-3011 | Cri | 0.64 | 9.8 | 0.01 | Mar 31, 2025 | SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | ||
| CVE-2025-28087 | Cri | 0.64 | 9.8 | 0.00 | Mar 28, 2025 | Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php. | ||
| CVE-2025-22953 | Cri | 0.64 | 9.8 | 0.02 | Mar 28, 2025 | A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this… | ||
| CVE-2025-30372 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2025 | Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after urldecode, allowing the preceeding addslashes to be bypassed by URL double encoding. This… | ||
| CVE-2025-30367 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.6 in the nextPage parameter of the /WeGIA/controle/control.php endpoint. This vulnerability allows attacker to manipulate SQL queries and access sensitive… | ||
| CVE-2025-30365 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/socio/sistema/controller/query_geracao_auto.php, specifically in the query parameter. This vulnerability allows the execution… | ||
| CVE-2025-30364 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/funcionario/remuneracao.php, in the id_funcionario parameter. This vulnerability allows the execution of arbitrary SQL… | ||
| CVE-2025-25686 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2025 | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. | ||
| CVE-2024-42533 | Cri | 0.64 | 9.8 | 0.01 | Mar 25, 2025 | SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter. |
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.
- risk 0.64cvss 9.8epss 0.01
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.
- risk 0.64cvss 9.8epss 0.00
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the…
- risk 0.64cvss 9.8epss 0.01
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
- risk 0.64cvss 9.8epss 0.06
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.
- risk 0.64cvss 9.8epss 0.01
Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1.
- risk 0.64cvss 9.8epss 0.01
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.
- risk 0.64cvss 9.8epss 0.01
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php.
- risk 0.64cvss 9.8epss 0.00
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.
- risk 0.64cvss —epss 0.01
Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page.
- risk 0.64cvss 9.8epss 0.01
SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
- risk 0.64cvss 9.8epss 0.00
Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.
- risk 0.64cvss 9.8epss 0.02
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this…
- risk 0.64cvss 9.8epss 0.01
Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after urldecode, allowing the preceeding addslashes to be bypassed by URL double encoding. This…
- risk 0.64cvss 9.8epss 0.01
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.6 in the nextPage parameter of the /WeGIA/controle/control.php endpoint. This vulnerability allows attacker to manipulate SQL queries and access sensitive…
- risk 0.64cvss 9.8epss 0.01
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/socio/sistema/controller/query_geracao_auto.php, specifically in the query parameter. This vulnerability allows the execution…
- risk 0.64cvss 9.8epss 0.01
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/funcionario/remuneracao.php, in the id_funcionario parameter. This vulnerability allows the execution of arbitrary SQL…
- risk 0.64cvss 9.8epss 0.01
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter.