CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,424)
page 726 of 1,022| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-51660 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php. | ||
| CVE-2025-51659 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php. | ||
| CVE-2025-51658 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php. | ||
| CVE-2025-51657 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php. | ||
| CVE-2025-51656 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php. | ||
| CVE-2025-51655 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php. | ||
| CVE-2025-51654 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php. | ||
| CVE-2025-51653 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php. | ||
| CVE-2025-51652 | Med | 0.35 | 5.4 | 0.00 | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php. | ||
| CVE-2025-45809 | Med | 0.35 | 5.4 | 0.00 | Jul 3, 2025 | SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints. | ||
| CVE-2025-51671 | Med | 0.35 | 5.4 | 0.00 | Jun 26, 2025 | A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file. | ||
| CVE-2023-45256 | Med | 0.35 | 5.4 | 0.00 | Jun 12, 2025 | Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, validation.php, or… | ||
| CVE-2025-29744 | Med | 0.35 | 5.4 | 0.00 | Jun 12, 2025 | pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers. | ||
| CVE-2024-44906 | Med | 0.35 | 6.5 | 0.00 | Jun 12, 2025 | uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is fixed in v1.2.15. | ||
| CVE-2024-44905 | Med | 0.35 | 6.5 | 0.00 | Jun 12, 2025 | go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go. | ||
| CVE-2025-48701 | Med | 0.35 | 5.4 | 0.00 | May 23, 2025 | openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used. | ||
| CVE-2024-40120 | Med | 0.35 | 6.5 | 0.00 | May 16, 2025 | seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go. | ||
| CVE-2025-2248 | Med | 0.35 | 5.4 | 0.00 | May 15, 2025 | The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | ||
| CVE-2024-9879 | Med | 0.35 | 5.4 | 0.00 | May 15, 2025 | The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | ||
| CVE-2024-9838 | Med | 0.35 | 5.4 | 0.00 | May 15, 2025 | The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks |
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
- risk 0.35cvss 5.4epss 0.00
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.
- risk 0.35cvss 5.4epss 0.00
SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.
- risk 0.35cvss 5.4epss 0.00
A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file.
- risk 0.35cvss 5.4epss 0.00
Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, MAC, reference, or aliascb parameter to transaction.php, validation.php, or…
- risk 0.35cvss 5.4epss 0.00
pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.
- risk 0.35cvss 6.5epss 0.00
uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is fixed in v1.2.15.
- risk 0.35cvss 6.5epss 0.00
go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
- risk 0.35cvss 5.4epss 0.00
openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.
- risk 0.35cvss 6.5epss 0.00
seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.
- risk 0.35cvss 5.4epss 0.00
The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
- risk 0.35cvss 5.4epss 0.00
The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
- risk 0.35cvss 5.4epss 0.00
The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks