VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 726 of 1,022
  • CVE-2025-51660MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.

  • CVE-2025-51659MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.

  • CVE-2025-51658MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.

  • CVE-2025-51657MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.

  • CVE-2025-51656MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.

  • CVE-2025-51655MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.

  • CVE-2025-51654MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.

  • CVE-2025-51653MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.

  • CVE-2025-51652MedJul 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.

  • CVE-2025-45809MedJul 3, 2025
    risk 0.35cvss 5.4epss 0.00

    SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

  • CVE-2025-51671MedJun 26, 2025
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file.

  • CVE-2023-45256MedJun 12, 2025
    risk 0.35cvss 5.4epss 0.00

    Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, validation.php, or…

  • CVE-2025-29744MedJun 12, 2025
    risk 0.35cvss 5.4epss 0.00

    pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.

  • CVE-2024-44906MedJun 12, 2025
    risk 0.35cvss 6.5epss 0.00

    uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is fixed in v1.2.15.

  • CVE-2024-44905MedJun 12, 2025
    risk 0.35cvss 6.5epss 0.00

    go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.

  • CVE-2025-48701MedMay 23, 2025
    risk 0.35cvss 5.4epss 0.00

    openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.

  • CVE-2024-40120MedMay 16, 2025
    risk 0.35cvss 6.5epss 0.00

    seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.

  • CVE-2025-2248MedMay 15, 2025
    risk 0.35cvss 5.4epss 0.00

    The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

  • CVE-2024-9879MedMay 15, 2025
    risk 0.35cvss 5.4epss 0.00

    The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

  • CVE-2024-9838MedMay 15, 2025
    risk 0.35cvss 5.4epss 0.00

    The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks