VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 51 of 1,041
  • CVE-2024-40073CriApr 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.

  • CVE-2024-40072CriApr 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.

  • CVE-2025-28100CriApr 15, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.

  • CVE-2025-25226CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the…

  • CVE-2025-29647CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.

  • CVE-2024-22611CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.06

    OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.

  • CVE-2025-29369CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.01

    Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1.

  • CVE-2025-22930CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.01

    OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.

  • CVE-2025-22929CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.01

    OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php.

  • CVE-2025-22928CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.00

    OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.

  • CVE-2025-3096CriApr 1, 2025
    risk 0.64cvss —epss 0.01

    Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page.

  • CVE-2025-3011CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2025-28087CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.00

    Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.

  • CVE-2025-22953CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this…

  • CVE-2025-30372CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.01

    Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after urldecode, allowing the preceeding addslashes to be bypassed by URL double encoding. This…

  • CVE-2025-30367CriMar 27, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.6 in the nextPage parameter of the /WeGIA/controle/control.php endpoint. This vulnerability allows attacker to manipulate SQL queries and access sensitive…

  • CVE-2025-30365CriMar 27, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/socio/sistema/controller/query_geracao_auto.php, specifically in the query parameter. This vulnerability allows the execution…

  • CVE-2025-30364CriMar 27, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/funcionario/remuneracao.php, in the id_funcionario parameter. This vulnerability allows the execution of arbitrary SQL…

  • CVE-2025-25686CriMar 27, 2025
    risk 0.64cvss 9.8epss 0.01

    semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.

  • CVE-2024-42533CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter.