CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,406 vulnerabilities with CWE-89
CVE-2026-44923
MEDIUM
InfoScale VIOM < 9.1.3 - SQL Injection
CVSS 6.5
CVE-2026-42383
HIGH
WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-9065
CRITICAL
Surecart - SQL Injection
CVE-2026-9059
CRITICAL
NextGEN Gallery - SQL Injection
CVE-2026-9010
HIGH
Boost <= 2.0.3 - Unauthenticated Blind SQL Injection via Multiple Parameters
CVSS 7.5
CVE-2026-9003
HIGH
TONNET|E-LAN Hybrid Recording System - SQL Injection
CVSS 7.5
CVE-2026-8685
MEDIUM
Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter
CVSS 6.5
CVE-2026-7472
MEDIUM
Read More & Accordion <= 3.5.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVSS 4.9
CVE-2026-3985
HIGH
Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uuid' Parameter
CVSS 7.5
CVE-2026-31069
HIGH
BillaBear - Authenticated SQL Injection via EventRepository Metric Filter Identifiers
CVSS 8.8
CVE-2026-8912
HIGH
Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-8827
HIGH
SQL Injection in extension "Address List" (tt_address)
CVE-2026-8726
HIGH
SQL Injection in extension "News system" (news)
CVE-2026-8851
HIGH
SOGo 5.12.7 SQL Injection via addUserInAcls endpoint
CVSS 8.1
CVE-2026-6379
HIGH
WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter
CVSS 8.6
CVE-2026-8785
HIGH
projectworlds hospital-management-system-in-php GET Parameter update_info.php getAllPatientDetail sql injection
CVSS 7.3
CVE-2026-8772
MEDIUM
linlinjava litemall Admin Endpoint sql injection
CVSS 4.7
CVE-2026-8771
HIGH
linlinjava litemall Front-end WeChat API WxGoodsController.java list sql injection
CVSS 7.3
CVE-2026-8734
HIGH
Oinone Pamirs queryListByWrapper RSQLToSQLNodeConnector.makeVariable sql injection
CVSS 7.3
CVE-2026-8724
MEDIUM
Dataease Data Dashboard SqlparserUtils.java SqlparserUtils.transFilter sql injection
CVSS 4.7
CVE-2026-46364
CRITICAL
phpMyFAQ - SQL Injection via User-Agent Header in BuiltinCaptcha
CVSS 9.8
CVE-2026-46359
HIGH
phpMyFAQ - SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token Fields
CVSS 7.5
CVE-2026-45800
HIGH
Vvveb: Authenticated SQL injection in /user/orders via order_by and direction
CVE-2026-7046
MEDIUM
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter
CVSS 4.9
CVE-2026-42847
HIGH
ClipBucket: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Details
Vulnerabilities
19,406
Exploit Likelihood
High