VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,200)

page 937 of 1,010
  • CVE-2026-13525MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulation of the argument emid results in sql…

  • CVE-2026-13521HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such manipulation of the argument course_year_section leads to sql injection. The attack may be…

  • CVE-2026-13520MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql injection. The attack is possible to be…

  • CVE-2026-49048CriJun 28, 2026
    risk 0.00cvss 9.8epss 0.01

    The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

  • CVE-2026-13498HigJun 28, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of the argument email leads to sql injection. The attack can be launched…

  • CVE-2026-13497MedJun 28, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the argument editid causes sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-13496MedJun 28, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid results in sql injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2026-13495MedJun 28, 2026
    risk 0.00cvss 4.7epss 0.00

    A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The manipulation of the argument loginid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-13488HigJun 28, 2026
    risk 0.00cvss 7.3epss 0.00

    A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file /preview7.php. The manipulation of the argument course_year_section results in sql injection. The attack may…

  • CVE-2026-13487HigJun 28, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The manipulation of the argument sy leads to sql injection. The attack may be initiated remotely. The exploit is publicly available…

  • CVE-2026-13486HigJun 28, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument course_year_section can lead to sql injection. The attack can be launched remotely.…

  • CVE-2026-13485HigJun 28, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection. The attack can be initiated remotely. The exploit…

  • CVE-2026-13333MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-13331MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in all versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-52785CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This…

  • CVE-2026-57667HigJun 26, 2026
    risk 0.00cvss 8.5epss 0.00

    Sales Representative SQL Injection in Groundhogg <= 4.5 versions.

  • CVE-2026-57663HigJun 26, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

  • CVE-2026-57662HigJun 26, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

  • CVE-2026-57653HigJun 26, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

  • CVE-2026-57644HigJun 26, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.