VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 713 of 1,022
  • CVE-2024-40068MedApr 16, 2025
    risk 0.38cvss 5.9epss 0.00

    Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.

  • CVE-2025-27892MedApr 15, 2025
    risk 0.38cvss 6.8epss 0.12

    Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

  • CVE-2025-28198MedApr 15, 2025
    risk 0.38cvss 5.9epss 0.00

    A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the orderBy parameter of the StoreController.java component.

  • CVE-2025-26157MedFeb 14, 2025
    risk 0.38cvss 5.9epss 0.00

    A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.

  • CVE-2024-57178MedFeb 10, 2025
    risk 0.38cvss 5.9epss 0.00

    An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be able the user data or…

  • CVE-2024-11722MedDec 21, 2024
    risk 0.38cvss 5.9epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

  • CVE-2024-28145MedDec 12, 2024
    risk 0.38cvss 5.9epss 0.01

    An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter…

  • CVE-2024-36801MedJun 4, 2024
    risk 0.38cvss 5.9epss 0.00

    A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.

  • CVE-2024-34222MedMay 14, 2024
    risk 0.38cvss 5.9epss 0.00

    Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

  • CVE-2024-25528MedMay 8, 2024
    risk 0.38cvss 5.9epss 0.00

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.

  • CVE-2024-33407MedMay 6, 2024
    risk 0.38cvss 5.9epss 0.00

    SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-25848MedMar 8, 2024
    risk 0.38cvss 5.9epss 0.00

    In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2024-24256MedFeb 15, 2024
    risk 0.38cvss 5.9epss 0.00

    SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory.

  • CVE-2023-31171MedAug 31, 2023
    risk 0.38cvss 5.9epss 0.00

    An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device…

  • CVE-2022-36839MedAug 5, 2022
    risk 0.38cvss 5.9epss 0.00

    SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information.

  • CVE-2022-30619MedJul 6, 2022
    risk 0.38cvss 5.9epss 0.01

    Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any authenticated user, in any kind of rule. under the function : /AgilePointServer/Extension/FetchUsingE…

  • CVE-2022-23169MedJun 13, 2022
    risk 0.38cvss 5.9epss 0.00

    attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.

  • CVE-2022-23168MedJun 13, 2022
    risk 0.38cvss 5.9epss 0.00

    The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'--

  • CVE-2022-1358MedMay 17, 2022
    risk 0.38cvss 5.9epss 0.01

    The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.

  • CVE-2022-0507MedMar 10, 2022
    risk 0.38cvss 5.8epss 0.01

    Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG version, up to OUM 759. This vulnerability could allow an attacker with authenticated IP to inject SQL.