VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,387)

page 773 of 1,020
  • CVE-2026-26890LowMar 3, 2026
    risk 0.18cvss 2.7epss 0.00

    Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php.

  • CVE-2026-26886LowMar 3, 2026
    risk 0.18cvss 2.7epss 0.00

    Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_service.php.

  • CVE-2026-26885LowMar 3, 2026
    risk 0.18cvss 2.7epss 0.00

    Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_service.

  • CVE-2026-26884LowMar 3, 2026
    risk 0.18cvss 2.7epss 0.00

    Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view_appointment.php.

  • CVE-2026-26883LowMar 3, 2026
    risk 0.18cvss 2.7epss 0.00

    Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=delete_appointment.

  • CVE-2025-24474LowJul 8, 2025
    risk 0.18cvss 2.7epss 0.00

    An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiManager Cloud 7.4.1 through 7.4.6, 7.2 all…

  • CVE-2022-29059LowMar 14, 2025
    risk 0.18cvss 2.7epss 0.00

    An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database…

  • CVE-2025-22212LowMar 5, 2025
    risk 0.18cvss 2.7epss 0.00

    A SQL injection vulnerability in the Convert Forms component versions 1.0.0-1.0.0 - 4.4.9 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the submission management area in backend.

  • CVE-2024-55593LowJan 14, 2025
    risk 0.18cvss 2.7epss 0.00

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries

  • CVE-2024-22261LowJun 11, 2024
    risk 0.18cvss 2.7epss 0.00

    SQL-Injection in Harbor allows priviledge users to leak the task IDs

  • CVE-2022-46498LowMar 7, 2024
    risk 0.18cvss 2.7epss 0.00

    Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.

  • CVE-2023-37361LowJul 25, 2023
    risk 0.18cvss 2.7epss 0.01

    REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization.

  • CVE-2022-3710LowDec 1, 2022
    risk 0.18cvss 2.7epss 0.01

    A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.

  • CVE-2022-28815LowSep 28, 2022
    risk 0.18cvss 2.7epss 0.00

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service.

  • CVE-2022-1690LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using them in a SQL statement in an admin page, leading to an SQL injection

  • CVE-2022-1689LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQL statement when updating a note via the admin dashboard, leading to an SQL injection

  • CVE-2022-1688LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various SQL statement via the admin dashboard, leading to SQL Injections

  • CVE-2022-1687LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it in a SQL statement via the Manage Slider Images admin page, leading to an SQL Injection

  • CVE-2022-1686LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection

  • CVE-2022-1684LowJun 8, 2022
    risk 0.18cvss 2.7epss 0.01

    The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in various SQL queries, leading to SQL Injections exploitable by high privileged users such as admin