CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 53 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-55160 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2025 | GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list. | ||
| CVE-2024-13148 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection. This issue affects B2B Login Platform: before 16.01.2025. | ||
| CVE-2025-1751 | Cri | 0.64 | 9.8 | 0.00 | Feb 27, 2025 | A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint. | ||
| CVE-2025-25521 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. | ||
| CVE-2025-25520 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. | ||
| CVE-2025-25519 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. | ||
| CVE-2025-25517 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. | ||
| CVE-2025-25516 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. | ||
| CVE-2025-27135 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to the database query. As of time of publication, no patched… | ||
| CVE-2025-22974 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2025 | SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component. | ||
| CVE-2024-53544 | Cri | 0.64 | 9.8 | 0.00 | Feb 24, 2025 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint. | ||
| CVE-2025-25513 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php. | ||
| CVE-2024-54820 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2025 | XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input. | ||
| CVE-2025-27096 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2025 | WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovered in the WeGIA application, personalizacao_upload.php endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing… | ||
| CVE-2025-26617 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,… | ||
| CVE-2025-26612 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `adicionar_almoxarife.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL… | ||
| CVE-2025-26611 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,… | ||
| CVE-2025-26610 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `restaurar_produto_desocultar.php` endpoint. This vulnerability allow an authorized attacker to execute… | ||
| CVE-2025-26609 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `familiar_docfamiliar.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL… | ||
| CVE-2025-26608 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `dependente_docdependente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL… |
- risk 0.64cvss 9.8epss 0.01
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.
- risk 0.64cvss 9.8epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection. This issue affects B2B Login Platform: before 16.01.2025.
- risk 0.64cvss 9.8epss 0.00
A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
- risk 0.64cvss 9.8epss 0.01
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to the database query. As of time of publication, no patched…
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
- risk 0.64cvss 9.8epss 0.00
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.
- risk 0.64cvss 9.8epss 0.01
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
- risk 0.64cvss 9.8epss 0.01
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.
- risk 0.64cvss 9.8epss 0.01
WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovered in the WeGIA application, personalizacao_upload.php endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing…
- risk 0.64cvss 9.8epss 0.01
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…
- risk 0.64cvss 9.8epss 0.01
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `adicionar_almoxarife.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…
- risk 0.64cvss 9.8epss 0.01
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…
- risk 0.64cvss 9.8epss 0.01
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `restaurar_produto_desocultar.php` endpoint. This vulnerability allow an authorized attacker to execute…
- risk 0.64cvss 9.8epss 0.01
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `familiar_docfamiliar.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…
- risk 0.64cvss 9.8epss 0.01
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `dependente_docdependente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…