VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 573 of 1,044
  • CVE-2021-47720HigDec 23, 2025
    risk 0.46cvss 7.1epss 0.00

    Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attackers can inject malicious SQL code into parameters like old_project_id, project_id, uuid, and uniqid…

  • CVE-2025-63497HigNov 10, 2025
    risk 0.46cvss 7.1epss 0.00

    The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization,…

  • CVE-2025-9339HigOct 21, 2025
    risk 0.46cvss —epss 0.00

    SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user a malicious query injection. Potential exploitation is limited by the 20-character limit in form fields. Identified use case allows to delete tables with a…

  • CVE-2025-10692HigOct 3, 2025
    risk 0.46cvss —epss 0.00

    The endpoint POST /api/staff/get-new-tickets concatenates the user-controlled parameter departmentId directly into the SQL WHERE clause without parameter binding. As a result, an authenticated staff user (level ≥ 1) can inject SQL to alter the filter logic, effectively…

  • CVE-2025-58375HigSep 6, 2025
    risk 0.46cvss 8.1epss 0.00

    Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved.…

  • CVE-2025-50383HigAug 25, 2025
    risk 0.46cvss 8.1epss 0.00

    alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.

  • CVE-2025-50466HigAug 8, 2025
    risk 0.46cvss 7.1epss 0.00

    OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType parameter can be used to build a SQL query.

  • CVE-2025-50465HigAug 8, 2025
    risk 0.46cvss 7.1epss 0.00

    OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL query.

  • CVE-2025-45346HigJul 29, 2025
    risk 0.46cvss 8.1epss 0.01

    SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.

  • CVE-2025-37104HigJul 16, 2025
    risk 0.46cvss 7.1epss 0.00

    A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized…

  • CVE-2025-6970HigJul 9, 2025
    risk 0.46cvss 7.5epss 0.56

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-27685HigJun 25, 2025
    risk 0.46cvss 7.1epss 0.00

    SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.

  • CVE-2025-3751HigMay 21, 2025
    risk 0.46cvss —epss 0.00

    The component listed above contains a vulnerability that can be exploited by an attacker to perform a SQL Injection attack. This could lead to unauthorised access to the database and exposure of sensitive information

  • CVE-2024-54447HigMar 14, 2025
    risk 0.46cvss —epss 0.00

    Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all database contents. Account takeover is a potential outcome depending on the presence or lack thereof…

  • CVE-2024-54446HigMar 14, 2025
    risk 0.46cvss —epss 0.00

    Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time-based blind SQLi technique the attacker can disclose all database contents. Account takeover is a potential outcome depending on the presence or lack…

  • CVE-2025-26533HigFeb 24, 2025
    risk 0.46cvss 8.1epss 0.01

    An SQL injection risk was identified in the module list filter within course search.

  • CVE-2025-22976HigJan 15, 2025
    risk 0.46cvss 7.1epss 0.00

    SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module.

  • CVE-2024-47977HigDec 10, 2024
    risk 0.46cvss 7.1epss 0.01

    Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially…

  • CVE-2024-11728HigDec 6, 2024
    risk 0.46cvss 7.5epss 0.14

    The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user…

  • CVE-2024-47881HigOct 24, 2024
    risk 0.46cvss 8.1epss 0.01

    OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote)…