VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 578 of 1,044
  • CVE-2025-55320MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.

  • CVE-2025-9140MedAug 19, 2025
    risk 0.44cvss 6.3epss 0.01

    A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this issue is some unknown functionality of the file /crm/crmapi/erp/tabdetail_moduleSave.php. The manipulation of the argument getvaluestring leads to sql…

  • CVE-2025-55156HigAug 11, 2025
    risk 0.44cvss —epss 0.00

    pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This…

  • CVE-2025-41233MedJun 12, 2025
    risk 0.44cvss 6.8epss 0.00

    Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate severity range https://www.broadcom.com/support/vmware-services/security-response  with a maximum CVSSv3…

  • CVE-2025-32466MedJun 11, 2025
    risk 0.44cvss —epss 0.00

    A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript…

  • CVE-2024-57151MedMar 18, 2025
    risk 0.44cvss 6.8epss 0.00

    SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function

  • CVE-2025-30022MedMar 14, 2025
    risk 0.44cvss 6.8epss 0.00

    CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.

  • CVE-2025-22207MedFeb 18, 2025
    risk 0.44cvss —epss 0.00

    Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.

  • CVE-2024-57095MedJan 24, 2025
    risk 0.44cvss 6.8epss 0.01

    SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.

  • CVE-2025-22980MedJan 22, 2025
    risk 0.44cvss 6.7epss 0.01

    A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.

  • CVE-2024-54761MedJan 9, 2025
    risk 0.44cvss 6.3epss 0.02

    BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

  • CVE-2024-8355MedNov 22, 2024
    risk 0.44cvss 6.8epss 0.01

    Visteon Infotainment System DeviceManager iAP Serial Number SQL Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Visteon Infotainment system. Authentication is not required to exploit this…

  • CVE-2024-49588MedNov 21, 2024
    risk 0.44cvss 6.8epss 0.00

    Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.

  • CVE-2024-47911MedOct 4, 2024
    risk 0.44cvss 6.7epss 0.00

    In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.

  • CVE-2024-39843MedSep 23, 2024
    risk 0.44cvss 6.7epss 0.02

    A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.

  • CVE-2024-6039MedJun 16, 2024
    risk 0.44cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of the argument dim leads to sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2023-46807MedMay 22, 2024
    risk 0.44cvss 6.7epss 0.01

    An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.

  • CVE-2023-46806MedMay 22, 2024
    risk 0.44cvss 6.7epss 0.01

    An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.

  • CVE-2024-33272MedApr 29, 2024
    risk 0.44cvss 6.8epss 0.00

    SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL commands via the AutosuggestSearchModuleFrontController::initContent(), and AutosuggestSearchModuleFrontController::getKbProducts() components.

  • CVE-2024-31212MedApr 4, 2024
    risk 0.44cvss 6.7epss 0.01

    InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data…