CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
18,856 vulnerabilities with CWE-89
CVE-2026-7592
HIGH
itsourcecode Courier Management System edit_staff.php sql injection
CVSS 7.3
CVE-2026-7591
MEDIUM
TimBroddin astro-mcp-server MCP Tool Query Construction index.ts sql injection
CVSS 6.3
CVE-2026-7555
HIGH
itsourcecode Electronic Judging System login.php sql injection
CVSS 7.3
CVE-2026-7553
MEDIUM
code-projects Gym Management System edit_exercises.php sql injection
CVSS 4.7
CVE-2026-7550
HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php save_customer sql injection
CVSS 7.3
CVE-2026-7549
HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_customer sql injection
CVSS 7.3
CVE-2026-7545
HIGH
SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection
CVSS 7.3
CVE-2026-7506
HIGH
SourceCodester Hotel Management System check sql injection
CVSS 7.3
CVE-2026-3346
MEDIUM
Stored Cross-Site Scripting (XSS) in Langflow Markdown Rendering via rehypeRaw
CVSS 6.4
CVE-2026-7435
HIGH
SSCMS v7.4.0 SQL Injection via stl:sqlContent queryString
CVSS 7.2
CVE-2026-7447
MEDIUM
SourceCodester Pet Grooming Management Software update_customer.php sql injection
CVSS 6.3
CVE-2026-7410
MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection
CVSS 6.3
CVE-2026-7409
MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection
CVSS 4.7
CVE-2026-7408
MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php save_menu sql injection
CVSS 4.7
CVE-2026-7407
MEDIUM
SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection
CVSS 4.7
CVE-2026-7394
MEDIUM
SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection
CVSS 4.7
CVE-2026-7392
MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection
CVSS 6.3
CVE-2026-7391
MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection
CVSS 6.3
CVE-2026-7389
HIGH
EyouCMS common.php GetSortData sql injection
CVSS 7.3
CVE-2026-42646
HIGH
WordPress TaxoPress plugin <= 3.44.0 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-3325
CRITICAL
SQL injection in MegaCMS by CRM Sistemas de Fidelización
CVE-2026-42167
HIGH
ProFTPD <1.3.10rc1 - RCE
CVSS 8.1
CVE-2026-7293
MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
CVSS 4.7
CVE-2026-7290
MEDIUM
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
CVSS 6.3
CVE-2026-7283
MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection
CVSS 4.7
Details
Vulnerabilities
18,856
Exploit Likelihood
High