CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,988 vulnerabilities with CWE-89
CVE-2026-15344 MEDIUM
WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter
CVSS 4.9
CVE-2026-54658 CRITICAL
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
CVSS 9.8
CVE-2026-6881 CRITICAL
Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance
CVE-2026-11391 MEDIUM
Tanium Patch - SQL Injection
CVSS 6.3
CVE-2026-7769 HIGH
IBM Sterling B2B Integrator and File Gateway - SQL Injection
CVSS 8.1
CVE-2026-50736 CRITICAL
Enterprisedb Pglogical < 2.4.8 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-15304 MEDIUM
Plugin Organizer <= 10.2.4 - Authenticated (Subscriber+) SQL Injection
CVSS 6.5
CVE-2026-15444 MEDIUM
Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter
CVSS 4.9
CVE-2026-16462 CRITICAL
Weidmueller Interface PROCON-WEB SCADA - SQL Injection via Unauthenticated GetGridData Endpoint
CVSS 9.8
CVE-2026-14785 HIGH
Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-10207 HIGH
PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter
CVSS 7.5
CVE-2026-15267 MEDIUM
Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection
CVSS 6.5
CVE-2026-14516 HIGH
Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-13161 HIGH
TrueBooker WordPress Plugin <= 1.2.2 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-12800 HIGH
Premium Packages <= 6.2.0 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-15673 MEDIUM
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings
CVSS 4.4
CVE-2026-15671 MEDIUM
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter
CVSS 4.9
CVE-2026-15670 MEDIUM
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVSS 4.9
CVE-2026-12741 HIGH
WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-6251 MEDIUM
Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter
CVSS 6.5
CVE-2026-16811 MEDIUM
ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVSS 4.9
CVE-2026-51077 HIGH
DedeCMS 5.7.118 - SQL Injection via sys_sql_query.php sqlquery Parameter
CVSS 7.5
CVE-2026-17191 CRITICAL
VeloCloud Orchestrator Flow Metrics API SQL Injection
CVSS 9.1
CVE-2026-66427 HIGH
WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-59551 HIGH
WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability
CVSS 8.5
Details
Vulnerabilities 19,988
Exploit Likelihood High