VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 715 of 1,022
  • CVE-2026-40828MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DeleteSysLogEntry function due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non…

  • CVE-2026-40827MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest function due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non critical…

  • CVE-2026-40825MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view devices parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a…

  • CVE-2026-40824MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view userid parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non…

  • CVE-2026-40823MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset function due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical…

  • CVE-2021-47714MedDec 22, 2025
    risk 0.36cvss 5.5epss 0.00

    Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the…

  • CVE-2025-29425MedMar 17, 2025
    risk 0.36cvss 5.5epss 0.00

    Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.

  • CVE-2025-25462MedFeb 26, 2025
    risk 0.36cvss 5.5epss 0.00

    A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.

  • CVE-2025-26348MedFeb 12, 2025
    risk 0.36cvss 5.5epss 0.01

    A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model.lua (editUserMenu endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to execute arbitrary SQL commands…

  • CVE-2025-26346MedFeb 12, 2025
    risk 0.36cvss 5.5epss 0.01

    A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model.lua (editUserGroupMenu endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to execute arbitrary SQL…

  • CVE-2024-13204MedJan 9, 2025
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /blog-details.php. The manipulation of the argument blog_id leads to sql injection. The attack can be launched…

  • CVE-2024-10841MedNov 5, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler. The manipulation of the argument Name leads to sql injection. The attack can…

  • CVE-2022-25775MedSep 18, 2024
    risk 0.36cvss 6.6epss 0.01

    Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.

  • CVE-2024-6803MedJul 17, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in itsourcecode Document Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert.php. The manipulation of the argument anothercont leads to sql injection. The attack can be…

  • CVE-2024-39072MedJul 9, 2024
    risk 0.36cvss 5.5epss 0.00

    AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calendar_remind.php.

  • CVE-2024-5098MedMay 19, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been found in SourceCodester Simple Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The exploit has been…

  • CVE-2024-30801MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.01

    SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.

  • CVE-2024-34472MedMay 6, 2024
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize…

  • CVE-2024-32872MedApr 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow…

  • CVE-2024-3466MedApr 8, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of the file /application/controller/Pengeluaran.php. The manipulation of the argument dari/sampai leads to…