CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,409 vulnerabilities with CWE-89
CVE-2026-42237 HIGH
n8n: SQL Injection in Snowflake and MySQL Nodes
CVSS 8.8
CVE-2026-42233 CRITICAL
n8n: SQL Injection in Oracle Database Node via Limit Field
CVSS 9.8
CVE-2026-42229 HIGH
n8n: SQL Injection in SeaTable Node
CVSS 8.8
CVE-2026-42087 CRITICAL
OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base
CVSS 9.6
CVE-2026-7746 MEDIUM
SourceCodester Web-based Pharmacy Product Management System edit-admin.php sql injection
CVSS 6.3
CVE-2026-7745 MEDIUM
CodeAstro Online Classroom facultydetails sql injection
CVSS 6.3
CVE-2026-7744 MEDIUM
CodeAstro Online Classroom addnewstudent sql injection
CVSS 6.3
CVE-2026-7743 MEDIUM
CodeAstro Online Classroom studentdetails sql injection
CVSS 6.3
CVE-2026-7742 MEDIUM
CodeAstro Online Classroom facultylogin sql injection
CVSS 6.3
CVE-2026-7741 MEDIUM
CodeAstro Online Classroom studentlogin sql injection
CVSS 6.3
CVE-2026-7731 MEDIUM
code-projects BloodBank Managing System get_state.php sql injection
CVSS 6.3
CVE-2026-7727 HIGH
Shandong Hoteam Software PDM Product Data Management System DataService GetQueryMachineGridOnePageData sql injection
CVSS 7.3
CVE-2026-7716 MEDIUM
code-projects Gym Management System In PHP/Windows NT index.php sql injection
CVSS 6.3
CVE-2026-7699 MEDIUM
Dromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injection
CVSS 6.3
CVE-2026-7697 MEDIUM
AMTT Hotel Broadband Operation System cardhand_submit.php sql injection
CVSS 4.7
CVE-2026-7695 HIGH
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform elecMaxMinAvgValue sql injection
CVSS 7.3
CVE-2026-7694 HIGH
Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue sql injection
CVSS 7.3
CVE-2026-7688 MEDIUM
Dolibarr ERP CRM Shipments API Endpoint expedition.class.php _checkValForAPI sql injection
CVSS 5.0
CVE-2026-7678 MEDIUM
YunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection
CVSS 6.3
CVE-2026-7672 MEDIUM
youlaitech youlai-boot Users Endpoint UserController.java getUserList sql injection
CVSS 6.3
CVE-2026-7670 HIGH
Jinher OA UserSel.aspx sql injection
CVSS 7.3
CVE-2026-7632 HIGH
code-projects Online Hospital Management System viewappointment.php sql injection
CVSS 7.3
CVE-2026-4062 HIGH
Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'object_ids' Parameter
CVSS 7.5
CVE-2026-4061 HIGH
Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'map_post_type' Parameter
CVSS 7.5
CVE-2026-4060 HIGH
Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'sort' Parameter
CVSS 7.5
Details
Vulnerabilities 19,409
Exploit Likelihood High