VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 53 of 1,041
  • CVE-2024-55160CriFeb 27, 2025
    risk 0.64cvss 9.8epss 0.01

    GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.

  • CVE-2024-13148CriFeb 27, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection. This issue affects B2B Login Platform: before 16.01.2025.

  • CVE-2025-1751CriFeb 27, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint.

  • CVE-2025-25521CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.

  • CVE-2025-25520CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.

  • CVE-2025-25519CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.

  • CVE-2025-25517CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.

  • CVE-2025-25516CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.

  • CVE-2025-27135CriFeb 25, 2025
    risk 0.64cvss 9.8epss 0.01

    RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to the database query. As of time of publication, no patched…

  • CVE-2025-22974CriFeb 24, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.

  • CVE-2024-53544CriFeb 24, 2025
    risk 0.64cvss 9.8epss 0.00

    NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.

  • CVE-2025-25513CriFeb 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

  • CVE-2024-54820CriFeb 24, 2025
    risk 0.64cvss 9.8epss 0.01

    XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

  • CVE-2025-27096CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovered in the WeGIA application, personalizacao_upload.php endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing…

  • CVE-2025-26617CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…

  • CVE-2025-26612CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `adicionar_almoxarife.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2025-26611CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries,…

  • CVE-2025-26610CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `restaurar_produto_desocultar.php` endpoint. This vulnerability allow an authorized attacker to execute…

  • CVE-2025-26609CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `familiar_docfamiliar.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…

  • CVE-2025-26608CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `dependente_docdependente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL…