CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,200)
page 937 of 1,010| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-13525 | Med | 0.00 | 6.3 | 0.00 | Jun 29, 2026 | A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql… | ||
| CVE-2026-13521 | Hig | 0.00 | 7.3 | 0.00 | Jun 29, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such manipulation of the argument course_year_section leads to sql injection. The attack may be… | ||
| CVE-2026-13520 | Med | 0.00 | 6.3 | 0.00 | Jun 29, 2026 | A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql injection. The attack is possible to be… | ||
| CVE-2026-49048 | Cri | 0.00 | 9.8 | 0.01 | Jun 28, 2026 | The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation. | ||
| CVE-2026-13498 | Hig | 0.00 | 7.3 | 0.00 | Jun 28, 2026 | A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of the argument email leads to sql injection. The attack can be launched… | ||
| CVE-2026-13497 | Med | 0.00 | 6.3 | 0.00 | Jun 28, 2026 | A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the argument editid causes sql injection. The attack can be initiated remotely. The exploit has been… | ||
| CVE-2026-13496 | Med | 0.00 | 6.3 | 0.00 | Jun 28, 2026 | A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid results in sql injection. It is possible to launch the attack remotely. The exploit… | ||
| CVE-2026-13495 | Med | 0.00 | 4.7 | 0.00 | Jun 28, 2026 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The manipulation of the argument loginid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | ||
| CVE-2026-13488 | Hig | 0.00 | 7.3 | 0.00 | Jun 28, 2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file /preview7.php. The manipulation of the argument course_year_section results in sql injection. The attack may… | ||
| CVE-2026-13487 | Hig | 0.00 | 7.3 | 0.00 | Jun 28, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The manipulation of the argument sy leads to sql injection. The attack may be initiated remotely. The exploit is publicly available… | ||
| CVE-2026-13486 | Hig | 0.00 | 7.3 | 0.00 | Jun 28, 2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument course_year_section can lead to sql injection. The attack can be launched remotely.… | ||
| CVE-2026-13485 | Hig | 0.00 | 7.3 | 0.00 | Jun 28, 2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection. The attack can be initiated remotely. The exploit… | ||
| CVE-2026-13333 | Med | 0.00 | 6.5 | 0.00 | Jun 27, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-13331 | Med | 0.00 | 6.5 | 0.00 | Jun 27, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-52785 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This… | ||
| CVE-2026-57667 | Hig | 0.00 | 8.5 | 0.00 | Jun 26, 2026 | Sales Representative SQL Injection in Groundhogg <= 4.5 versions. | ||
| CVE-2026-57663 | Hig | 0.00 | 8.5 | 0.00 | Jun 26, 2026 | Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions. | ||
| CVE-2026-57662 | Hig | 0.00 | 8.5 | 0.00 | Jun 26, 2026 | Contributor SQL Injection in Contest Gallery <= 30.0.0 versions. | ||
| CVE-2026-57653 | Hig | 0.00 | 8.5 | 0.00 | Jun 26, 2026 | Contributor SQL Injection in WP Job Portal <= 2.5.2 versions. | ||
| CVE-2026-57644 | Hig | 0.00 | 8.5 | 0.00 | Jun 26, 2026 | Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions. |
- risk 0.00cvss 6.3epss 0.00
A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql…
- risk 0.00cvss 7.3epss 0.00
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such manipulation of the argument course_year_section leads to sql injection. The attack may be…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql injection. The attack is possible to be…
- risk 0.00cvss 9.8epss 0.01
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.
- risk 0.00cvss 7.3epss 0.00
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of the argument email leads to sql injection. The attack can be launched…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the argument editid causes sql injection. The attack can be initiated remotely. The exploit has been…
- risk 0.00cvss 6.3epss 0.00
A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid results in sql injection. It is possible to launch the attack remotely. The exploit…
- risk 0.00cvss 4.7epss 0.00
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The manipulation of the argument loginid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
- risk 0.00cvss 7.3epss 0.00
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file /preview7.php. The manipulation of the argument course_year_section results in sql injection. The attack may…
- risk 0.00cvss 7.3epss 0.00
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The manipulation of the argument sy leads to sql injection. The attack may be initiated remotely. The exploit is publicly available…
- risk 0.00cvss 7.3epss 0.00
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument course_year_section can lead to sql injection. The attack can be launched remotely.…
- risk 0.00cvss 7.3epss 0.00
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection. The attack can be initiated remotely. The exploit…
- risk 0.00cvss 6.5epss 0.00
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.00cvss 6.5epss 0.00
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.00cvss 9.9epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This…
- risk 0.00cvss 8.5epss 0.00
Sales Representative SQL Injection in Groundhogg <= 4.5 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.