CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,424)
page 734 of 1,022| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-25106 | Med | 0.34 | 6.3 | 0.00 | Dec 23, 2024 | A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection. The attack may be… | ||
| CVE-2024-49773 | Med | 0.34 | 5.3 | 0.00 | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled input is used to build SQL query. `current_post` parameter in `export`… | ||
| CVE-2024-32231 | Med | 0.34 | 6.3 | 0.01 | Aug 15, 2024 | Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter. | ||
| CVE-2024-41238 | Med | 0.34 | 5.3 | 0.00 | Aug 8, 2024 | A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | ||
| CVE-2024-6933 | Med | 0.34 | 6.3 | 0.01 | Jul 21, 2024 | A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler.… | ||
| CVE-2024-35357 | Med | 0.34 | 5.3 | 0.00 | May 30, 2024 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_item. Manipulating the argument id can result in SQL injection. | ||
| CVE-2024-34930 | Med | 0.34 | 5.3 | 0.00 | May 23, 2024 | A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the month parameter. | ||
| CVE-2024-36039 | Med | 0.34 | 6.3 | 0.01 | May 21, 2024 | PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict. | ||
| CVE-2024-33161 | — | Med | 0.34 | 5.3 | 0.00 | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function. | |
| CVE-2024-30861 | Med | 0.34 | 5.3 | 0.00 | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php. | ||
| CVE-2024-24407 | Med | 0.34 | 5.3 | 0.01 | Mar 28, 2024 | SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component. | ||
| CVE-2024-25896 | Med | 0.34 | 5.3 | 0.00 | Feb 21, 2024 | ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter. | ||
| CVE-2023-48261 | Med | 0.34 | 5.3 | 0.01 | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request. | ||
| CVE-2023-48260 | Med | 0.34 | 5.3 | 0.01 | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request. | ||
| CVE-2023-48259 | Med | 0.34 | 5.3 | 0.01 | Jan 10, 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request. | ||
| CVE-2023-44088 | Med | 0.34 | 5.9 | 0.01 | Dec 29, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700… | ||
| CVE-2023-29047 | Med | 0.34 | 5.3 | 0.00 | Nov 2, 2023 | Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content… | ||
| CVE-2007-10003 | Med | 0.34 | 6.3 | 0.01 | Oct 29, 2023 | A vulnerability, which was classified as critical, has been found in The Hackers Diet Plugin up to 0.9.6b on WordPress. This issue affects some unknown processing of the file ajax_blurb.php of the component HTTP POST Request Handler. The manipulation of the argument user leads… | ||
| CVE-2015-10126 | Med | 0.34 | 6.3 | 0.01 | Oct 6, 2023 | A vulnerability classified as critical was found in Easy2Map Photos Plugin 1.0.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.1.0 is able to address this issue. The… | ||
| CVE-2015-10124 | Med | 0.34 | 6.3 | 0.01 | Oct 2, 2023 | A vulnerability was found in Most Popular Posts Widget Plugin up to 0.8 on WordPress. It has been classified as critical. Affected is the function add_views/show_views of the file functions.php. The manipulation leads to sql injection. It is possible to launch the attack… |
- risk 0.34cvss 6.3epss 0.00
A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to sql injection. The attack may be…
- risk 0.34cvss 5.3epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled input is used to build SQL query. `current_post` parameter in `export`…
- risk 0.34cvss 6.3epss 0.01
Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
- risk 0.34cvss 5.3epss 0.00
A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.
- risk 0.34cvss 6.3epss 0.01
A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler.…
- risk 0.34cvss 5.3epss 0.00
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_item. Manipulating the argument id can result in SQL injection.
- risk 0.34cvss 5.3epss 0.00
A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the month parameter.
- risk 0.34cvss 6.3epss 0.01
PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
- risk 0.34cvss 5.3epss 0.00
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.
- risk 0.34cvss 5.3epss 0.00
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.
- risk 0.34cvss 5.3epss 0.01
SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.
- risk 0.34cvss 5.3epss 0.00
ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.
- risk 0.34cvss 5.3epss 0.01
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.
- risk 0.34cvss 5.3epss 0.01
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.
- risk 0.34cvss 5.3epss 0.01
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.
- risk 0.34cvss 5.9epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700…
- risk 0.34cvss 5.3epss 0.00
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content…
- risk 0.34cvss 6.3epss 0.01
A vulnerability, which was classified as critical, has been found in The Hackers Diet Plugin up to 0.9.6b on WordPress. This issue affects some unknown processing of the file ajax_blurb.php of the component HTTP POST Request Handler. The manipulation of the argument user leads…
- risk 0.34cvss 6.3epss 0.01
A vulnerability classified as critical was found in Easy2Map Photos Plugin 1.0.1 on WordPress. This vulnerability affects unknown code. The manipulation leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.1.0 is able to address this issue. The…
- risk 0.34cvss 6.3epss 0.01
A vulnerability was found in Most Popular Posts Widget Plugin up to 0.8 on WordPress. It has been classified as critical. Affected is the function add_views/show_views of the file functions.php. The manipulation leads to sql injection. It is possible to launch the attack…