CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,424)
page 733 of 1,022| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-5328 | Med | 0.34 | 6.3 | 0.00 | Apr 2, 2026 | A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listItem of the file src/main/java/com/suisung/shopsuite/pt/service/impl/ProductIndexServiceImpl.java of the component ProductItemDao… | ||
| CVE-2026-4530 | Med | 0.34 | 5.3 | 0.00 | Mar 22, 2026 | A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py. Performing a manipulation of the argument Description results in sql injection. The attack requires a local approach. The… | ||
| CVE-2026-26745 | Med | 0.34 | 5.3 | 0.00 | Feb 20, 2026 | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper… | ||
| CVE-2025-12812 | Med | 0.34 | — | 0.00 | Feb 18, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed in Cloud Suite: 25.1 | ||
| CVE-2023-38913 | Med | 0.34 | 5.3 | 0.01 | Dec 15, 2025 | SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script. | ||
| CVE-2023-36338 | Med | 0.34 | 5.3 | 0.00 | Dec 15, 2025 | Inventory Management System 1 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2025-13168 | Med | 0.34 | 6.3 | 0.00 | Nov 14, 2025 | A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py. This manipulation of the argument search_term causes sql injection. Remote exploitation of the attack is possible. The exploit… | ||
| CVE-2025-40888 | Med | 0.34 | 5.3 | 0.00 | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing… | ||
| CVE-2025-40887 | Med | 0.34 | 5.3 | 0.00 | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing… | ||
| CVE-2025-40885 | Med | 0.34 | 5.3 | 0.00 | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially… | ||
| CVE-2025-10095 | Med | 0.34 | — | 0.00 | Sep 9, 2025 | A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically affecting the handling of certain parameters within the server's database interactions. The vulnerability is isolated to the SMPP server, which operates with its… | ||
| CVE-2025-56435 | Med | 0.34 | 5.3 | 0.00 | Sep 3, 2025 | SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on the parameter id. | ||
| CVE-2025-50984 | Med | 0.34 | 5.3 | 0.00 | Aug 27, 2025 | diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsanitized user input in POST parameters such as ES_PASS, ES_MAXSIZE, ES_TRANSLOGSIZE, ES_TIMEOUT, ES_USER, ES_HOST, ES_PORT,… | ||
| CVE-2025-6230 | Med | 0.34 | 5.3 | 0.00 | Jul 17, 2025 | A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands. | ||
| CVE-2025-32753 | Med | 0.34 | 5.3 | 0.00 | Jun 20, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial… | ||
| CVE-2025-30507 | Med | 0.34 | 5.3 | 0.00 | Jun 9, 2025 | CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections. | ||
| CVE-2025-48743 | Med | 0.34 | 5.3 | 0.00 | May 27, 2025 | SIGB PMB before 8.0.1.2 allows SQL injection. | ||
| CVE-2025-45021 | Med | 0.34 | 5.3 | 0.00 | Apr 30, 2025 | A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands. | ||
| CVE-2025-27018 | Med | 0.34 | 6.3 | 0.01 | Mar 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by… | ||
| CVE-2025-22370 | Med | 0.34 | — | 0.00 | Mar 11, 2025 | Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized. |
- risk 0.34cvss 6.3epss 0.00
A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listItem of the file src/main/java/com/suisung/shopsuite/pt/service/impl/ProductIndexServiceImpl.java of the component ProductItemDao…
- risk 0.34cvss 5.3epss 0.00
A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py. Performing a manipulation of the argument Description results in sql injection. The attack requires a local approach. The…
- risk 0.34cvss 5.3epss 0.00
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper…
- risk 0.34cvss —epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Privileged Access Service. Remediation: This issue is fixed in Cloud Suite: 25.1
- risk 0.34cvss 5.3epss 0.01
SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.
- risk 0.34cvss 5.3epss 0.00
Inventory Management System 1 was discovered to contain a SQL injection vulnerability.
- risk 0.34cvss 6.3epss 0.00
A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py. This manipulation of the argument search_term causes sql injection. Remote exploitation of the attack is possible. The exploit…
- risk 0.34cvss 5.3epss 0.00
A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing…
- risk 0.34cvss 5.3epss 0.00
A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing…
- risk 0.34cvss 5.3epss 0.00
A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially…
- risk 0.34cvss —epss 0.00
A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle firmware, specifically affecting the handling of certain parameters within the server's database interactions. The vulnerability is isolated to the SMPP server, which operates with its…
- risk 0.34cvss 5.3epss 0.00
SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on the parameter id.
- risk 0.34cvss 5.3epss 0.00
diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsanitized user input in POST parameters such as ES_PASS, ES_MAXSIZE, ES_TRANSLOGSIZE, ES_TIMEOUT, ES_USER, ES_HOST, ES_PORT,…
- risk 0.34cvss 5.3epss 0.00
A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.
- risk 0.34cvss 5.3epss 0.00
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial…
- risk 0.34cvss 5.3epss 0.00
CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.
- risk 0.34cvss 5.3epss 0.00
SIGB PMB before 8.0.1.2 allows SQL injection.
- risk 0.34cvss 5.3epss 0.00
A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands.
- risk 0.34cvss 6.3epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by…
- risk 0.34cvss —epss 0.00
Many fields for the web configuration interface of the firmware for Mennekes Smart / Premium Chargingpoints can be abused to execute arbitrary SQL commands because the values are insufficiently neutralized.