VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 576 of 1,044
  • CVE-2026-78070MedAug 28, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.

  • CVE-2026-72807HigAug 12, 2026
    risk 0.45cvss 8.0epss 0.00

    SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan…

  • CVE-2026-38739higMay 29, 2026
    risk 0.45cvss —epss 0.00

    NB: All tags and branches in this repository are past their end of life, so the vulnerability will not be fixed. The advisory is posted on the request of the researcher, for the information of anyone who might still use this software. ### Impact There is a security…

  • CVE-2026-32813HigMar 20, 2026
    risk 0.45cvss 8.0epss 0.00

    Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layouts, storing user-supplied…

  • CVE-2025-30062MedMar 2, 2026
    risk 0.45cvss —epss 0.00

    In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.

  • CVE-2025-30061MedAug 27, 2025
    risk 0.45cvss —epss 0.00

    In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parameter.

  • CVE-2025-30060MedAug 27, 2025
    risk 0.45cvss —epss 0.00

    In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" parameter.

  • CVE-2025-30059MedAug 27, 2025
    risk 0.45cvss —epss 0.00

    In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.

  • CVE-2025-30058MedAug 27, 2025
    risk 0.45cvss —epss 0.00

    In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter.

  • CVE-2025-34136MedJul 25, 2025
    risk 0.45cvss —epss 0.00

    An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server…

  • CVE-2024-13973MedJul 21, 2025
    risk 0.45cvss 6.8epss 0.10

    A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.

  • CVE-2025-53122MedJun 26, 2025
    risk 0.45cvss —epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection.  Users should upgrade to Meridian 2024.2.6 or newer, or Horizon 33.16 or newer. Meridian and Horizon…

  • CVE-2025-1520HigApr 23, 2025
    risk 0.45cvss 8.0epss 0.00

    PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PostHog. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2025-2126MedMar 9, 2025
    risk 0.45cvss 6.3epss 0.11

    A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties of the component GET Parameter Handler. The…

  • CVE-2024-12745HigDec 24, 2024
    risk 0.45cvss 8.0epss 0.01

    A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.

  • CVE-2024-12744HigDec 24, 2024
    risk 0.45cvss 8.0epss 0.01

    A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.

  • CVE-2024-4658MedOct 10, 2024
    risk 0.45cvss —epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TE Informatics Nova CMS allows SQL Injection. This issue affects Nova CMS: before 5.0.

  • CVE-2024-7801MedOct 4, 2024
    risk 0.45cvss 6.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

  • CVE-2024-23115HigApr 1, 2024
    risk 0.45cvss 7.2epss 0.67

    Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2023-1545HigMar 21, 2023
    risk 0.45cvss 7.5epss 0.08

    SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.