VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,200)

page 936 of 1,010
  • CVE-2026-40523HigJun 29, 2026
    risk 0.00cvss 8.1epss 0.00

    FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authenticated attackers with SA_GLANALYTIC permission to execute arbitrary SQL queries by injecting malicious code into the PARAM_2 and PARAM_3 POST parameters.…

  • CVE-2026-40522HigJun 29, 2026
    risk 0.00cvss 7.1epss 0.00

    FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL…

  • CVE-2026-13569MedJun 29, 2026
    risk 0.00cvss 4.7epss 0.00

    A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processing of the file /index.php of the component API. Such manipulation of the argument click_like leads to sql injection. The attack can be executed remotely. The…

  • CVE-2026-13566HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /preview3.php. The manipulation of the argument course_year_section leads to sql injection. The attack may be initiated…

  • CVE-2026-13565HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_class1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be…

  • CVE-2026-13559HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been…

  • CVE-2026-13555HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation of the argument Name results in sql injection. The attack can be launched…

  • CVE-2026-13552HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the argument amen_id results in sql injection. It is possible to initiate…

  • CVE-2026-13551HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an unknown function of the file /editBaptism.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit…

  • CVE-2026-13550HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unknown function of the file /delbaptism.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2026-13548MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /doctortimings.php. The manipulation of the argument editid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly…

  • CVE-2026-13542MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2026-13541MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /doctorchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The attack may be performed from remote. The…

  • CVE-2026-13535MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulation of the argument ID can lead to sql…

  • CVE-2026-13532MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /departmentDoctor.php. This manipulation of the argument deptid causes sql injection. It is possible to initiate the attack…

  • CVE-2026-13531MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /department.php. The manipulation of the argument editid results in sql injection. The attack may be performed from remote. The exploit has been…

  • CVE-2026-13530MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be…

  • CVE-2026-13529MedJun 29, 2026
    risk 0.00cvss 5.6epss 0.00

    A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remotely. A high complexity level is associated…

  • CVE-2026-13527HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /preview4.php. Such manipulation of the argument course_year_section leads to sql injection. The attack may be launched remotely. The…

  • CVE-2026-13526HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_class.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be…