CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,988 vulnerabilities with CWE-89
CVE-2026-15344
MEDIUM
WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter
CVSS 4.9
CVE-2026-54658
CRITICAL
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
CVSS 9.8
CVE-2026-6881
CRITICAL
Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance
CVE-2026-11391
MEDIUM
Tanium Patch - SQL Injection
CVSS 6.3
CVE-2026-7769
HIGH
IBM Sterling B2B Integrator and File Gateway - SQL Injection
CVSS 8.1
CVE-2026-50736
CRITICAL
Enterprisedb Pglogical < 2.4.8 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-15304
MEDIUM
Plugin Organizer <= 10.2.4 - Authenticated (Subscriber+) SQL Injection
CVSS 6.5
CVE-2026-15444
MEDIUM
Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter
CVSS 4.9
CVE-2026-16462
CRITICAL
Weidmueller Interface PROCON-WEB SCADA - SQL Injection via Unauthenticated GetGridData Endpoint
CVSS 9.8
CVE-2026-14785
HIGH
Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-10207
HIGH
PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter
CVSS 7.5
CVE-2026-15267
MEDIUM
Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection
CVSS 6.5
CVE-2026-14516
HIGH
Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-13161
HIGH
TrueBooker WordPress Plugin <= 1.2.2 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-12800
HIGH
Premium Packages <= 6.2.0 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-15673
MEDIUM
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings
CVSS 4.4
CVE-2026-15671
MEDIUM
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter
CVSS 4.9
CVE-2026-15670
MEDIUM
SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVSS 4.9
CVE-2026-12741
HIGH
WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-6251
MEDIUM
Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter
CVSS 6.5
CVE-2026-16811
MEDIUM
ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVSS 4.9
CVE-2026-51077
HIGH
DedeCMS 5.7.118 - SQL Injection via sys_sql_query.php sqlquery Parameter
CVSS 7.5
CVE-2026-17191
CRITICAL
VeloCloud Orchestrator Flow Metrics API SQL Injection
CVSS 9.1
CVE-2026-66427
HIGH
WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-59551
HIGH
WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability
CVSS 8.5
Details
Vulnerabilities
19,988
Exploit Likelihood
High