VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,387)

page 778 of 1,020
  • CVE-2008-5191Nov 21, 2008
    risk 0.04cvss epss 0.18

    Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.php and the (2) sp_id parameter to staticpages.php.

  • CVE-2008-1613Apr 22, 2008
    risk 0.04cvss epss 0.08

    SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter.

  • CVE-2008-0690Feb 12, 2008
    risk 0.04cvss epss 0.09

    SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewcat action.

  • CVE-2007-6318Dec 12, 2007
    risk 0.04cvss epss 0.09

    SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a…

  • CVE-2006-0586Feb 8, 2006
    risk 0.04cvss epss 0.07

    Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5)…

  • CVE-2006-0146Jan 9, 2006
    risk 0.04cvss epss 0.13

    The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to…

  • CVE-2003-0845Nov 17, 2003
    risk 0.04cvss epss 0.15

    Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port…

  • CVE-2026-57588LowJun 25, 2026
    risk 0.03cvss 3.3epss 0.00

    A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

  • CVE-2024-54146HigJan 27, 2025
    risk 0.03cvss 7.6epss 0.41

    Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template parameter. This vulnerability is fixed in 1.2.29.

  • CVE-2024-1601CriApr 16, 2024
    risk 0.03cvss 9.8epss 0.40

    An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete all discussions and message data. The vulnerability is exploitable via a crafted HTTP POST request to the `/delete_discussion`…

  • CVE-2023-5350CriOct 3, 2023
    risk 0.03cvss 9.1epss 0.02

    SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

  • CVE-2023-31714CriAug 30, 2023
    risk 0.03cvss 9.8epss 0.03

    Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.

  • CVE-2022-34878MedJul 5, 2022
    risk 0.03cvss 5.5epss 0.03

    SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise…

  • CVE-2022-34877MedJul 5, 2022
    risk 0.03cvss 6.4epss 0.03

    SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make…

  • CVE-2022-34876MedJul 5, 2022
    risk 0.03cvss 5.5epss 0.03

    SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email parameters allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system,…

  • CVE-2020-9483HigJun 30, 2020
    risk 0.03cvss 7.5epss 0.35

    **Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use…

  • CVE-2019-14430MedAug 20, 2019
    risk 0.03cvss 5.3epss 0.03

    plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.

  • CVE-2018-9250HigMay 18, 2018
    risk 0.03cvss 8.8epss 0.32

    interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.

  • CVE-2018-10757CriMay 5, 2018
    risk 0.03cvss 9.8epss 0.06

    CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.

  • CVE-2015-7903Oct 28, 2015
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.