CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,424)
page 736 of 1,022| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-10011 | Med | 0.34 | 6.3 | 0.01 | Jan 12, 2023 | A vulnerability was found in aeharding classroom-engagement-system and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection. The attack may be launched remotely. The name of the patch is… | ||
| CVE-2015-10008 | Med | 0.34 | 6.3 | 0.01 | Jan 2, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The identifier of the patch is… | ||
| CVE-2020-36631 | Med | 0.34 | 6.3 | 0.01 | Dec 25, 2022 | A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerability affects the function update_profile of the file gamespy/gs_database.py. The manipulation of the argument firstname/lastname leads to sql injection. The… | ||
| CVE-2022-45205 | Med | 0.34 | 5.3 | 0.01 | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. | ||
| CVE-2022-39069 | Med | 0.34 | 5.3 | 0.00 | Nov 8, 2022 | There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attack by building malicious requests. Exploitation of this vulnerability could cause the leakage of the current table content. | ||
| CVE-2022-3827 | Med | 0.34 | 6.3 | 0.01 | Nov 2, 2022 | A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated… | ||
| CVE-2022-3802 | Med | 0.34 | 6.3 | 0.01 | Nov 1, 2022 | A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiated remotely. The exploit has been… | ||
| CVE-2022-3800 | Med | 0.34 | 6.3 | 0.02 | Nov 1, 2022 | A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. The attack may be launched remotely. The… | ||
| CVE-2022-3799 | Med | 0.34 | 6.3 | 0.01 | Nov 1, 2022 | A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | ||
| CVE-2022-3798 | Med | 0.34 | 6.3 | 0.01 | Nov 1, 2022 | A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | ||
| CVE-2020-11010 | Med | 0.34 | 6.3 | 0.01 | Apr 20, 2020 | In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and… | ||
| CVE-2026-7688 | — | Med | 0.33 | 5.0 | 0.00 | May 3, 2026 | A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file htdocs/expedition/class/expedition.class.php of the component Shipments API Endpoint. The manipulation of the argument fields leads to sql injection. The attack… | |
| CVE-2025-46053 | Med | 0.33 | 5.1 | 0.00 | May 15, 2025 | A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php | ||
| CVE-2023-33770 | Med | 0.33 | 5.1 | 0.00 | May 6, 2025 | Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php. | ||
| CVE-2025-26047 | Med | 0.33 | 5.1 | 0.00 | Feb 28, 2025 | Loggrove v1.0 is vulnerable to SQL Injection in the read.py file. | ||
| CVE-2020-19248 | Med | 0.33 | 5.1 | 0.00 | Feb 21, 2025 | SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse… | ||
| CVE-2025-25993 | Med | 0.33 | 5.1 | 0.00 | Feb 14, 2025 | SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid." | ||
| CVE-2025-25992 | Med | 0.33 | 5.1 | 0.00 | Feb 14, 2025 | SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component. | ||
| CVE-2025-25991 | Med | 0.33 | 5.1 | 0.00 | Feb 14, 2025 | SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component. | ||
| CVE-2024-30872 | Med | 0.33 | 5.1 | 0.00 | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php. |
- risk 0.34cvss 6.3epss 0.01
A vulnerability was found in aeharding classroom-engagement-system and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection. The attack may be launched remotely. The name of the patch is…
- risk 0.34cvss 6.3epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The identifier of the patch is…
- risk 0.34cvss 6.3epss 0.01
A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerability affects the function update_profile of the file gamespy/gs_database.py. The manipulation of the argument firstname/lastname leads to sql injection. The…
- risk 0.34cvss 5.3epss 0.01
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
- risk 0.34cvss 5.3epss 0.00
There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attack by building malicious requests. Exploitation of this vulnerability could cause the leakage of the current table content.
- risk 0.34cvss 6.3epss 0.01
A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated…
- risk 0.34cvss 6.3epss 0.01
A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiated remotely. The exploit has been…
- risk 0.34cvss 6.3epss 0.02
A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. The attack may be launched remotely. The…
- risk 0.34cvss 6.3epss 0.01
A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the…
- risk 0.34cvss 6.3epss 0.01
A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may…
- risk 0.34cvss 6.3epss 0.01
In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and…
- risk 0.33cvss 5.0epss 0.00
A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file htdocs/expedition/class/expedition.class.php of the component Shipments API Endpoint. The manipulation of the argument fields leads to sql injection. The attack…
- risk 0.33cvss 5.1epss 0.00
A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php
- risk 0.33cvss 5.1epss 0.00
Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php.
- risk 0.33cvss 5.1epss 0.00
Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.
- risk 0.33cvss 5.1epss 0.00
SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse…
- risk 0.33cvss 5.1epss 0.00
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."
- risk 0.33cvss 5.1epss 0.00
SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.
- risk 0.33cvss 5.1epss 0.00
SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
- risk 0.33cvss 5.1epss 0.00
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.