CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,988 vulnerabilities with CWE-89
CVE-2026-63221 CRITICAL
CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions
CVSS 9.4
CVE-2026-62845 MEDIUM
Kamaji: SQL injection via unescaped datastore identifiers in PostgreSQL/MySQL drivers
CVSS 4.7
CVE-2026-4978 CRITICAL
SQLi in UMAI Vision's Traffic Analysis System
CVSS 9.8
CVE-2026-54368 HIGH
CentreStack < 17.4 SQL Injection via x-glad-filter Header
CVSS 8.8
CVE-2026-17543 HIGH
SQL injection in ext-pgsql via E'...' backslash breakout
CVE-2026-22620 HIGH
Eaton Padm < 20 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS 8.6
CVE-2026-58046 CRITICAL
Webpros Plesk - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS 9.9
CVE-2026-15153 MEDIUM
WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search
CVSS 6.8
CVE-2026-13395 HIGH
Online Scheduling and Appointment Booking System < 27.8 - SQL Injection
CVSS 8.6
CVE-2026-48448 HIGH
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
CVSS 8.6
CVE-2026-16092 MEDIUM
Improved Save Button <= 1.2.1 - Authenticated (Author+) Second-Order SQL Injection via 'meta_key' Parameter
CVSS 6.5
CVE-2026-15929 HIGH
LG Electronics SmartShare < 2.3.1712.1202 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-5490 HIGH
DriveLock SQL Injection Privilege Escalation Vulnerability
CVSS 8.8
CVE-2026-8339 HIGH
SQL Injection in Coverity Connect SOAP API
CVE-2026-51992 CRITICAL
ClickHouse Server <= 26.3.9.8 - Remote Code Execution via PostgreSQL Dictionary Creation
CVSS 9.1
CVE-2026-65890 CRITICAL
Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2
CVE-2026-33385 MEDIUM
Blind SQL Injection in Quick.CMS
CVE-2026-12895 HIGH
SQL Injection in Frappe's ERPNext
CVE-2026-11973 MEDIUM
WP-Lister Lite for eBay <= 3.8.8 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVSS 4.9
CVE-2026-63234 CRITICAL
Three Learning Koollab Lms < 5.3.2 - SQL Injection
CVSS 9.9
CVE-2026-63233 CRITICAL
Three Learning Koollab Lms < 5.3.2 - SQL Injection
CVSS 9.9
CVE-2026-63232 CRITICAL
Three Learning Koollab Lms < 5.3.2 - SQL Injection
CVSS 9.9
CVE-2026-63231 HIGH
Three Learning Koollab Lms < 5.3.2 - SQL Injection
CVSS 8.1
CVE-2026-63230 CRITICAL
Three Learning Koollab Lms < 5.3.2 - SQL Injection
CVSS 9.1
CVE-2026-63229 CRITICAL
Three Learning Koollab Lms < 5.3.2 - SQL Injection
CVSS 9.1
Details
Vulnerabilities 19,988
Exploit Likelihood High