CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
18,080 vulnerabilities with CWE-89
CVE-2026-3818
HIGH
Tiandy Easy7 CMS 7.17.0 - SQL Injection
CVSS 7.3
CVE-2025-40639
Eventobot - SQL Injection
CVE-2026-3806
MEDIUM
janobe Resort Reservation System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3793
MEDIUM
SourceCodester Sales and Inventory System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3792
MEDIUM
SourceCodester Sales and Inventory System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3791
MEDIUM
SourceCodester Sales and Inventory System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3790
MEDIUM
SourceCodester Sales and Inventory System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3786
MEDIUM
EasyCMS <1.6 - SQL Injection
CVSS 6.3
CVE-2026-3785
MEDIUM
EasyCMS <=1.6 - SQL Injection
CVSS 6.3
CVE-2026-3771
MEDIUM
janobe Resort Reservation System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3767
MEDIUM
itsourcecode sanitize 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3765
HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3760
HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3759
HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3758
HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3757
HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3756
MEDIUM
SourceCodester Sales and Inventory System <1.0 - SQL Injection
CVSS 6.3
CVE-2026-3755
MEDIUM
SourceCodester Sales and Inventory System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3754
MEDIUM
SourceCodester Sales and Inventory System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3753
MEDIUM
SourceCodester Sales and Inventory System <1.0 - SQL Injection
CVSS 6.3
CVE-2026-3752
MEDIUM
SourceCodester Employee Task Management System <1.0 - SQL Injection
CVSS 4.7
CVE-2026-3751
MEDIUM
SourceCodester Employee Task Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2026-3747
HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3746
HIGH
SourceCodester Tourism Website 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3745
MEDIUM
Student Web Portal 1.0 - SQL Injection
CVSS 6.3
Details
Vulnerabilities
18,080
Exploit Likelihood
High