CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,409 vulnerabilities with CWE-89
CVE-2026-7389 HIGH
EyouCMS common.php GetSortData sql injection
CVSS 7.3
CVE-2026-42646 HIGH
WordPress TaxoPress plugin <= 3.44.0 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-3325 CRITICAL
SQL injection in MegaCMS by CRM Sistemas de Fidelización
CVE-2026-42167 HIGH
ProFTPD < 1.3.10rc1 - Remote Code Execution
CVSS 8.1
CVE-2026-7293 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
CVSS 4.7
CVE-2026-7290 MEDIUM
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
CVSS 6.3
CVE-2026-7283 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection
CVSS 4.7
CVE-2026-7282 MEDIUM
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_expired sql injection
CVSS 4.7
CVE-2026-7268 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php save_category sql injection
CVSS 6.3
CVE-2026-7267 MEDIUM
SourceCodester Pizzafy Ecommerce System view_prod.php sql injection
CVSS 6.3
CVE-2026-7266 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php save_order sql injection
CVSS 6.3
CVE-2026-7265 MEDIUM
SourceCodester Pizzafy Ecommerce System index.php category sql injection
CVSS 6.3
CVE-2026-7264 MEDIUM
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injection
CVSS 6.3
CVE-2026-40978 HIGH
Spring AI 1.0.0-1.0.5 1.1.0-1.1.4 - SQL Injection via CosmosDBVectorStore Document ID
CVSS 8.8
CVE-2026-7229 MEDIUM
code-projects Coaching Management System POST reply.php sql injection
CVSS 6.3
CVE-2026-7228 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
CVSS 7.3
CVE-2026-7227 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php login sql injection
CVSS 7.3
CVE-2026-7226 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php login2 sql injection
CVSS 7.3
CVE-2026-7225 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injection
CVSS 7.3
CVE-2026-7224 HIGH
SourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injection
CVSS 7.3
CVE-2026-7206 HIGH
dubydu sqlite-mcp entry.py extract_to_json sql injection
CVSS 7.3
CVE-2026-7199 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-7196 MEDIUM
CodeAstro Online Classroom guestdetails sql injection
CVSS 6.3
CVE-2026-7194 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-5394 HIGH
Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling
Details
Vulnerabilities 19,409
Exploit Likelihood High