CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,653 vulnerabilities with CWE-89
CVE-2024-56804 HIGH
Video Station <5.8.4 - SQL Injection
CVSS 8.8
CVE-2024-13150 CRITICAL
Fayton Pro ERP <20250929 - SQL Injection
CVSS 9.8
CVE-2024-13174 HIGH
E1 Informatics Web Application <20250916 - SQL Injection
CVSS 8.6
CVE-2024-13149 CRITICAL
Arma Store Armalife <20250916 - SQL Injection
CVSS 9.8
CVE-2024-12913 HIGH
Megatek Communication System Azora Wireless Network Management <202...
CVSS 8.8
CVE-2024-13979 CRITICAL
St. Joe ERP System - Unauthenticated SQL Injection via Login Endpoint
CVSS 9.8
CVE-2024-48988 HIGH
Apache StreamPark 2.1.4-2.1.5 - Authenticated SQL Injection
CVSS 7.6
CVE-2024-53499 CRITICAL
Jeewms v3.7 - SQL Injection via CgReportController API
CVSS 9.8
CVE-2024-12612 HIGH
School Management System for Wordpress <93.2.0 - SQL Injection
CVSS 7.5
CVE-2024-32640 CRITICAL
MASA CMS <7.4.5-7.2.7 - SQL Injection
CVSS 9.8
CVE-2024-34327 MEDIUM
Sielox AnyWare <2.1.2 - SQL Injection
CVSS 6.5
CVE-2024-45955 HIGH
Rocket Software Zena 4.4.1.26 - SQL Injection via Filter Parameter
CVSS 7.3
CVE-2024-43018 MEDIUM
Piwigo < 13.8.0 - SQL Injection via max_level and min_register Parameters
CVSS 6.4
CVE-2024-13507 HIGH
GeoDirectory - WP Business Directory Plugin <2.8.97 - SQL Injection
CVSS 7.5
CVE-2024-13973 MEDIUM
Sophos Firewall < 21.0.1 - Authenticated SQL Injection in WebAdmin
CVSS 6.8
CVE-2024-32323 HIGH
cnhcit.com Haichang OA <1.0.0 - SQL Injection
CVSS 8.1
CVE-2024-12364 CRITICAL
Mavi Yeşil Guest Tracking Software - SQL Injection
CVSS 9.8
CVE-2024-12150 CRITICAL
Eron Software Wowwo CRM - SQL Injection
CVSS 9.8
CVE-2024-12143 CRITICAL
Mobilteg Mobile Informatics Mikro Hand Terminal - MikroDB - SQL Inj...
CVSS 9.8
CVE-2024-11739 CRITICAL
Case ERP < V2.0.1 - SQL Injection
CVSS 9.8
CVE-2024-27685 HIGH
Student Record system <3.20 - SQL Injection
CVSS 7.1
CVE-2024-40570 MEDIUM
SeaCMS 12.9 - SQL Injection via admin_datarelate.php
CVSS 6.5
CVE-2024-44906 MEDIUM
uptrace pgdriver <1.2.1 - SQL Injection
CVSS 6.5
CVE-2024-44905 MEDIUM
go-pg <v10.13.0 - SQL Injection
CVSS 6.5
CVE-2024-56158 CRITICAL
XWiki < 15.10.16 - SQL Injection via Oracle DBMS_XMLGEN Function
CVSS 9.8
Details
Vulnerabilities 19,653
Exploit Likelihood High