CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 97 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0600 | Cri | 0.64 | 9.8 | 0.04 | May 15, 2023 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks. | ||
| CVE-2023-30246 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2023 | SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the contestant_id parameter. | ||
| CVE-2023-30192 | Cri | 0.64 | 9.8 | 0.03 | May 12, 2023 | Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find(). | ||
| CVE-2023-29863 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2023 | Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files. | ||
| CVE-2023-30092 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter. | ||
| CVE-2022-4118 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users | ||
| CVE-2020-23966 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request. | ||
| CVE-2023-30018 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=. | ||
| CVE-2023-30242 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2023 | NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php. | ||
| CVE-2023-30203 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php. | ||
| CVE-2023-30077 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id. | ||
| CVE-2023-30204 | Cri | 0.64 | 9.8 | 0.01 | May 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php. | ||
| CVE-2023-26813 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do. | ||
| CVE-2023-26781 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | ||
| CVE-2023-30211 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | OURPHP <= 7.2.0 is vulnerable to SQL Injection. | ||
| CVE-2023-27843 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component. | ||
| CVE-2023-26865 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2023 | SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component. | ||
| CVE-2023-23753 | Cri | 0.64 | 9.8 | 0.01 | Apr 23, 2023 | The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it. | ||
| CVE-2023-30076 | Cri | 0.64 | 9.8 | 0.01 | Apr 20, 2023 | Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=. | ||
| CVE-2023-1873 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection. This issue affects Bircard: before 23.04.05. |
- risk 0.64cvss 9.8epss 0.04
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the contestant_id parameter.
- risk 0.64cvss 9.8epss 0.03
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
- risk 0.64cvss 9.8epss 0.01
Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.
- risk 0.64cvss 9.8epss 0.01
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.
- risk 0.64cvss 9.8epss 0.01
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
- risk 0.64cvss 9.8epss 0.01
OURPHP <= 7.2.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.
- risk 0.64cvss 9.8epss 0.01
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection. This issue affects Bircard: before 23.04.05.