CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,409 vulnerabilities with CWE-89
CVE-2026-7612 MEDIUM
itsourcecode Courier Management System edit_user.php sql injection
CVSS 4.7
CVE-2026-7489 HIGH
Sunnet|CTMS - SQL Injection
CVSS 8.8
CVE-2026-7649 HIGH
ARMember <= 4.0.60 - Unauthenticated SQL Injection via 'orderby' Parameter
CVSS 7.5
CVE-2026-6457 MEDIUM
Geo Mashup <= 1.13.19 - Authenticated (Subscriber+) SQL Injection via 'geo_mashup_null_fields' Parameter
CVSS 6.5
CVE-2026-7592 HIGH
itsourcecode Courier Management System edit_staff.php sql injection
CVSS 7.3
CVE-2026-7591 MEDIUM
TimBroddin astro-mcp-server MCP Tool Query Construction index.ts sql injection
CVSS 6.3
CVE-2026-42475 MEDIUM
MixPHP Framework 2.x-2.2.17 - SQL Injection
CVSS 6.5
CVE-2026-42474 MEDIUM
MixPHP Framework 2.x-2.2.17 - SQL Injection
CVSS 6.5
CVE-2026-37505 MEDIUM
v2board < 1.7.4 - Authenticated SQL Injection via ORDER BY Clause
CVSS 4.9
CVE-2026-7555 HIGH
itsourcecode Electronic Judging System login.php sql injection
CVSS 7.3
CVE-2026-7553 MEDIUM
code-projects Gym Management System edit_exercises.php sql injection
CVSS 4.7
CVE-2026-7550 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php save_customer sql injection
CVSS 7.3
CVE-2026-7549 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_customer sql injection
CVSS 7.3
CVE-2026-7545 HIGH
SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection
CVSS 7.3
CVE-2026-7506 HIGH
SourceCodester Hotel Management System check sql injection
CVSS 7.3
CVE-2026-7435 HIGH
SSCMS v7.4.0 SQL Injection via stl:sqlContent queryString
CVSS 7.2
CVE-2026-3346 MEDIUM
Stored Cross-Site Scripting (XSS) in Langflow Markdown Rendering via rehypeRaw
CVSS 6.4
CVE-2026-7447 MEDIUM
SourceCodester Pet Grooming Management Software update_customer.php sql injection
CVSS 6.3
CVE-2026-7410 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection
CVSS 6.3
CVE-2026-7409 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection
CVSS 4.7
CVE-2026-7408 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php save_menu sql injection
CVSS 4.7
CVE-2026-7407 MEDIUM
SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection
CVSS 4.7
CVE-2026-7394 MEDIUM
SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection
CVSS 4.7
CVE-2026-7392 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection
CVSS 6.3
CVE-2026-7391 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection
CVSS 6.3
Details
Vulnerabilities 19,409
Exploit Likelihood High