VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 580 of 1,044
  • CVE-2023-0904MedFeb 18, 2023
    risk 0.44cvss 6.3epss 0.02

    A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file task-details.php. The manipulation of the argument task_id leads to sql injection. The attack may be initiated…

  • CVE-2023-23824MedJan 23, 2023
    risk 0.44cvss 6.7epss 0.01

    Auth. SQL Injection (SQLi) vulnerability in WP-TopBar <= 5.36 versions.

  • CVE-2022-22794MedFeb 24, 2022
    risk 0.44cvss 6.8epss 0.01

    Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1…

  • CVE-2021-21924MedDec 22, 2021
    risk 0.44cvss 6.5epss 0.20

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘desc_filter’ parameter.

  • CVE-2020-3984MedNov 24, 2020
    risk 0.44cvss 6.5epss 0.22

    The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call using specially crafted SQL queries which may lead to…

  • CVE-2020-14069MedJun 29, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, pppoe.php, queues.php, and wifi.php.

  • CVE-2016-8025MedMar 14, 2017
    risk 0.44cvss 6.2epss 0.07

    SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter.

  • CVE-2026-54647HigSep 17, 2026
    risk 0.43cvss 7.2epss 0.01

    CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated…

  • CVE-2026-54646HigSep 17, 2026
    risk 0.43cvss 7.2epss 0.01

    CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An…

  • CVE-2026-53557HigSep 17, 2026
    risk 0.43cvss —epss 0.00

    SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, and SQLBot stores that value…

  • CVE-2026-55208HigJul 9, 2026
    risk 0.43cvss 7.7epss 0.00

    Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin password hash and other database content through time-based blind SQL injection in the DateFilter column key parameter. The POST…

  • CVE-2026-27768MedMay 25, 2026
    risk 0.43cvss 6.6epss 0.00

    SQL Injection affecting the Access Manager role.

  • CVE-2026-32271HigApr 13, 2026
    risk 0.43cvss —epss 0.01

    Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through…

  • CVE-2026-24031HigMar 27, 2026
    risk 0.43cvss 7.7epss 0.00

    Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No…

  • CVE-2026-31891HigMar 18, 2026
    risk 0.43cvss 7.7epss 0.00

    Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the…

  • CVE-2025-12197HigNov 5, 2025
    risk 0.43cvss 7.5epss 0.18

    The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2024-35275MedJan 14, 2025
    risk 0.43cvss 6.6epss 0.01

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.

  • CVE-2024-45600HigDec 26, 2024
    risk 0.43cvss 7.7epss 0.00

    Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.

  • CVE-2024-21514HigJun 22, 2024
    risk 0.43cvss 7.4epss 0.19

    This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart, which is included by default in version 3.0.3.9. As an anonymous unauthenticated user, if the Divido payment module is installed…

  • CVE-2023-34975MedOct 13, 2023
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the…