VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,200)

page 944 of 1,010
  • CVE-2025-23220CriJan 20, 2025
    risk 0.00cvss 9.8epss 0.01

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_raca.php endpoint. This vulnerability allows attackers to execute…

  • CVE-2025-23219CriJan 20, 2025
    risk 0.00cvss 9.8epss 0.01

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_cor.php endpoint. This vulnerability allows attackers to execute…

  • CVE-2025-23218CriJan 20, 2025
    risk 0.00cvss 9.8epss 0.01

    WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_especie.php endpoint. This vulnerability allows attackers to execute…

  • CVE-2025-21628CriJan 9, 2025
    risk 0.00cvss 9.1epss 0.01

    Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator passed from the frontend or the API. This provided any actor who is authenticated, an attack vector to run arbitrary SQL within the…

  • CVE-2024-48814HigJan 3, 2025
    risk 0.00cvss 7.5epss 0.01

    SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function

  • CVE-2024-56801CriDec 30, 2024
    risk 0.00cvss 9.8epss 0.01

    Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.

  • CVE-2024-12895MedDec 22, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by this vulnerability is the function console_log of the file TreasureHunt/checkflag.php. The manipulation of the argument problema leads to sql injection. The…

  • CVE-2024-12894MedDec 22, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in TreasureHuntGame TreasureHunt up to 963e0e0. Affected is an unknown function of the file TreasureHunt/acesso.php. The manipulation of the argument usuario leads to sql injection. It is possible to launch the attack…

  • CVE-2024-55953HigDec 18, 2024
    risk 0.00cvss 8.1epss 0.01

    DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through the background JDBC connection. When constructing the jdbc connection string, the parameters are not filtered. This vulnerability has been fixed in v1.18.27.…

  • CVE-2024-49203Nov 20, 2024
    risk 0.00cvss epss 0.00

    Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Querydsl community member because the product is not intended to defend against a developer who uses untrusted input directly in query construction.

  • CVE-2024-11124MedNov 12, 2024
    risk 0.00cvss 4.7epss 0.00

    A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown code of the file /src/UIOMatic/wwwroot/backoffice/resources/uioMaticObject.r. The manipulation leads to sql injection. The attack can be initiated remotely.…

  • CVE-2024-48257CriOct 14, 2024
    risk 0.00cvss 9.8epss 0.01

    Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.

  • CVE-2024-48251CriOct 14, 2024
    risk 0.00cvss 9.8epss 0.01

    Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

  • CVE-2024-48249HigOct 14, 2024
    risk 0.00cvss 7.3epss 0.00

    Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

  • CVE-2024-7099CriOct 13, 2024
    risk 0.00cvss 9.8epss 0.01

    netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and…

  • CVE-2024-46257MedSep 27, 2024
    risk 0.00cvss 6.3epss 0.01

    A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.

  • CVE-2024-8332MedAug 30, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been declared as critical. This vulnerability affects unknown code of the file /table/index. The manipulation leads to sql injection. The attack can be initiated remotely.…

  • CVE-2024-45059HigAug 28, 2024
    risk 0.00cvss 8.8epss 0.01

    i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was found prior to the 2.9 branch in the `ieducar/intranet/funcionario_vinculo_det.php` file, which creates…

  • CVE-2024-43360CriAug 12, 2024
    risk 0.00cvss 9.8epss 0.06

    ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.

  • CVE-2023-41884HigAug 12, 2024
    risk 0.00cvss 7.1epss 0.01

    ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.