CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,387)
page 772 of 1,020| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-36938 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php. | ||
| CVE-2026-36937 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php. | ||
| CVE-2026-36945 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/clients/manage_client.php | ||
| CVE-2026-36944 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/admin/repairs/view_details.php. | ||
| CVE-2026-36943 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/repairs/manage_repair.php. | ||
| CVE-2026-36942 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php. | ||
| CVE-2026-36941 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php. | ||
| CVE-2026-36947 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/admin/services/view_service.php. | ||
| CVE-2026-36946 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php. | ||
| CVE-2026-36923 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php. | ||
| CVE-2026-36922 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category.php. | ||
| CVE-2026-36920 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php. | ||
| CVE-2026-36919 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php. | ||
| CVE-2026-36874 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php. | ||
| CVE-2026-36873 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php. | ||
| CVE-2026-36872 | Low | 0.18 | 2.7 | 0.00 | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php. | ||
| CVE-2026-26891 | Low | 0.18 | 2.7 | 0.00 | Mar 3, 2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php. | ||
| CVE-2026-26889 | Low | 0.18 | 2.7 | 0.00 | Mar 3, 2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php. | ||
| CVE-2026-26888 | Low | 0.18 | 2.7 | 0.00 | Mar 3, 2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php. | ||
| CVE-2026-26887 | Low | 0.18 | 2.7 | 0.00 | Mar 3, 2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php. |
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/clients/manage_client.php
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/admin/repairs/view_details.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/repairs/manage_repair.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/admin/services/view_service.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/inquiries/view_details.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php.
- risk 0.18cvss 2.7epss 0.00
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php.