CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 533 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-1793 | Hig | 0.47 | 7.2 | 0.01 | Mar 13, 2024 | The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 7.3.14 due to insufficient escaping on the user… | ||
| CVE-2024-1068 | Hig | 0.47 | 7.2 | 0.01 | Mar 11, 2024 | The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins. | ||
| CVE-2024-2264 | Hig | 0.47 | 7.3 | 0.01 | Mar 7, 2024 | A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched… | ||
| CVE-2023-49968 | Hig | 0.47 | 7.3 | 0.00 | Mar 5, 2024 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php. | ||
| CVE-2024-27515 | Hig | 0.47 | 7.2 | 0.01 | Feb 28, 2024 | Osclass 5.1.2 is vulnerable to SQL Injection. | ||
| CVE-2024-24027 | Hig | 0.47 | 7.2 | 0.01 | Feb 27, 2024 | SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function DistributionMemberLogic::getFansLists. | ||
| CVE-2024-24323 | Hig | 0.47 | 7.2 | 0.01 | Feb 27, 2024 | SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component. | ||
| CVE-2024-1826 | Hig | 0.47 | 7.3 | 0.01 | Feb 23, 2024 | A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file Source/librarian/user/student/login.php. The manipulation of the argument username/password leads to sql injection. The attack can… | ||
| CVE-2024-1824 | Hig | 0.47 | 7.3 | 0.01 | Feb 23, 2024 | A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file signing.php. The manipulation of the argument uname/password leads to sql injection. The attack may… | ||
| CVE-2024-1820 | Hig | 0.47 | 7.3 | 0.01 | Feb 23, 2024 | A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. The manipulation of the argument email/password leads to sql injection. The attack can be initiated… | ||
| CVE-2024-1776 | Hig | 0.47 | 7.2 | 0.01 | Feb 23, 2024 | The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | ||
| CVE-2023-52155 | Hig | 0.47 | 7.2 | 0.01 | Feb 21, 2024 | A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through the /admin/sauvegarde/run.php endpoint. | ||
| CVE-2024-25213 | Hig | 0.47 | 7.2 | 0.01 | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php. | ||
| CVE-2024-25212 | Hig | 0.47 | 7.2 | 0.01 | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php. | ||
| CVE-2024-1197 | Hig | 0.47 | 7.3 | 0.01 | Feb 2, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file delete-testimonial.php of the component HTTP GET Request Handler. The manipulation of the argument testimony… | ||
| CVE-2024-24140 | Hig | 0.47 | 7.2 | 0.01 | Jan 29, 2024 | Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.' | ||
| CVE-2024-24139 | Hig | 0.47 | 7.2 | 0.01 | Jan 29, 2024 | Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter. | ||
| CVE-2024-0405 | Hig | 0.47 | 7.2 | 0.01 | Jan 17, 2024 | The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id',… | ||
| CVE-2024-22628 | Hig | 0.47 | 7.2 | 0.01 | Jan 16, 2024 | Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end= | ||
| CVE-2024-22627 | Hig | 0.47 | 7.2 | 0.01 | Jan 16, 2024 | Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=. |
- risk 0.47cvss 7.2epss 0.01
The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 7.3.14 due to insufficient escaping on the user…
- risk 0.47cvss 7.2epss 0.01
The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.
- risk 0.47cvss 7.3epss 0.01
A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched…
- risk 0.47cvss 7.3epss 0.00
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.
- risk 0.47cvss 7.2epss 0.01
Osclass 5.1.2 is vulnerable to SQL Injection.
- risk 0.47cvss 7.2epss 0.01
SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function DistributionMemberLogic::getFansLists.
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component.
- risk 0.47cvss 7.3epss 0.01
A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file Source/librarian/user/student/login.php. The manipulation of the argument username/password leads to sql injection. The attack can…
- risk 0.47cvss 7.3epss 0.01
A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file signing.php. The manipulation of the argument uname/password leads to sql injection. The attack may…
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. The manipulation of the argument email/password leads to sql injection. The attack can be initiated…
- risk 0.47cvss 7.2epss 0.01
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
- risk 0.47cvss 7.2epss 0.01
A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through the /admin/sauvegarde/run.php endpoint.
- risk 0.47cvss 7.2epss 0.01
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.
- risk 0.47cvss 7.2epss 0.01
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.
- risk 0.47cvss 7.3epss 0.01
A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file delete-testimonial.php of the component HTTP GET Request Handler. The manipulation of the argument testimony…
- risk 0.47cvss 7.2epss 0.01
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
- risk 0.47cvss 7.2epss 0.01
Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
- risk 0.47cvss 7.2epss 0.01
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id',…
- risk 0.47cvss 7.2epss 0.01
Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=
- risk 0.47cvss 7.2epss 0.01
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=.