CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,402 vulnerabilities with CWE-89
CVE-2026-9364
HIGH
projectworlds Online Art Gallery Shop adminHome.php sql injection
CVSS 7.3
CVE-2026-9356
HIGH
SourceCodester Hospitals Patient Records Management System manage_history.php sql injection
CVSS 7.3
CVE-2026-9355
HIGH
SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injection
CVSS 7.3
CVE-2026-9342
MEDIUM
SourceCodester Hospitals Patient Records Management System view_history.php sql injection
CVSS 6.3
CVE-2026-9305
MEDIUM
QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection
CVSS 6.3
CVE-2026-41075
HIGH
RT: SQL injection via entry_aggregator parameter in JSON search
CVSS 8.8
CVE-2026-25606
HIGH
SQL Injection in STER
CVE-2026-4834
HIGH
WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter
CVSS 7.5
CVE-2026-48240
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and f_tick_id Parameters
CVSS 7.1
CVE-2026-48239
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter
CVSS 7.1
CVE-2026-48238
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter
CVSS 7.1
CVE-2026-48237
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and frm_resp_id Parameters
CVSS 7.1
CVE-2026-48236
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters
CVSS 7.1
CVE-2026-48235
HIGH
Open ISES Tickets < 3.44.2 SQL Injection in incs/remotes.inc.php via External GPS Tracker Data
CVSS 8.2
CVE-2026-48234
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php sort and dir Parameters
CVSS 7.1
CVE-2026-48233
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset Parameter
CVSS 7.1
CVE-2026-48232
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offset Parameter
CVSS 7.1
CVE-2026-48231
HIGH
Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters
CVSS 7.1
CVE-2026-39531
CRITICAL
WordPress WP Directory Kit plugin <= 1.5.0 - SQL Injection vulnerability
CVSS 9.3
CVE-2026-44047
HIGH
Netatalk 3.1.0-4.4.2 - Authenticated SQL Injection in MySQL CNID Backend
CVSS 8.8
CVE-2026-9082
CRITICAL
KEV
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
CVSS 9.8
CVE-2026-44923
MEDIUM
InfoScale VIOM < 9.1.3 - SQL Injection
CVSS 6.5
CVE-2026-42383
HIGH
WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-9065
CRITICAL
Surecart - SQL Injection
CVE-2026-9059
CRITICAL
NextGEN Gallery - SQL Injection
Details
Vulnerabilities
19,402
Exploit Likelihood
High