CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,410 vulnerabilities with CWE-89
CVE-2026-7060 HIGH
liyupi yu-picture MyBatis-Plus PictureServiceImpl.java PageRequest sql injection
CVSS 7.3
CVE-2026-7028 MEDIUM
CodeAstro Online Job Portal All Jobs delete-jobs.php sql injection
CVSS 4.7
CVE-2026-7023 MEDIUM
ByteDance coze-studio databaseTool database_impl.go ExecuteSQL sql injection
CVSS 6.3
CVE-2026-7002 HIGH
KLiK SocialMediaWebsite Private Message get_message_ajax.php sql injection
CVSS 7.3
CVE-2026-6991 MEDIUM
colinhacks Zod CUID Data Type regexes.ts sql injection
CVSS 6.3
CVE-2026-6982 MEDIUM
star7th ShowDoc API Page Sort Endpoint PageController.class.PHP sql injection
CVSS 6.3
CVE-2026-6978 MEDIUM
JiZhiCMS addcache.html htmlspecialchars_decode sql injection
CVSS 4.7
CVE-2026-41478 CRITICAL
Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)
CVSS 9.9
CVE-2026-33078 CRITICAL
Roxy-WI has SQL Injection in haproxy_section_save Endpoint via Unsanitized server_ip Parameter
CVSS 9.8
CVE-2026-31952 HIGH
Xibo CMS API has SQL Injection via DataSet Filter Parameter
CVSS 7.6
CVE-2026-41460 CRITICAL
SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall
CVSS 9.8
CVE-2026-6887 CRITICAL
BorG Technology Corporation|Borg SPM 2007 - SQL Injection
CVSS 9.8
CVE-2026-40529 MEDIUM
CMS ALAYA < 7.4.1.4 - Authenticated SQL Injection
CVSS 4.7
CVE-2026-29198 CRITICAL
Rocket.Chat <8.3.0 NoSQL Injection via OAuth App Configuration
CVSS 9.8
CVE-2026-41167 CRITICAL
Jellystat has SQL Injection that leads to to Remote Code Execution
CVSS 9.1
CVE-2026-6833 MEDIUM
aEnrich|a+HRD - SQL Injection
CVSS 6.5
CVE-2026-41457 MEDIUM
OwnTone Server < 29.1 SQL Injection via query and filter Parameters
CVE-2026-40906 CRITICAL
Electric: SQL Injection via ORDER BY Parameter in Shape API
CVSS 9.9
CVE-2026-41320 MEDIUM
Frappe HR has possibility of SQL Injection due to improper field sanitization
CVSS 6.5
CVE-2026-40887 CRITICAL
Vendure Shop API - SQL Injection
CVSS 9.1
CVE-2026-40871 HIGH
mailcow: dockerized vulnerable to Second Order SQL Injection in quarantine category via API
CVSS 7.2
CVE-2026-6674 MEDIUM
Plugin: CMS für Motorrad Werkstätten <= 1.0.0 - Authenticated (Subscriber+) SQL Injection via 'arttype' Parameter
CVSS 6.5
CVE-2026-39946 MEDIUM
OpenBao allows SQL Injection in PostgreSQL database secrets engine
CVSS 4.9
CVE-2026-35588 MEDIUM
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
CVSS 6.3
CVE-2026-39111 HIGH
Apartment Visitors Management System 1.1 - SQL Injection
CVSS 7.5
Details
Vulnerabilities 19,410
Exploit Likelihood High