CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,493 vulnerabilities with CWE-89
CVE-2026-5837 HIGH
PHPGurukul News Portal Project news-details.php sql injection
CVSS 7.3
CVE-2026-5829 HIGH
code-projects Simple IT Discussion Forum content.php sql injection
CVSS 7.3
CVE-2026-5828 HIGH
code-projects Simple IT Discussion Forum addcomment.php sql injection
CVSS 7.3
CVE-2026-5827 HIGH
code-projects Simple IT Discussion Forum question-function.php sql injection
CVSS 7.3
CVE-2026-5824 HIGH
code-projects Simple Laundry System userchecklogin.php sql injection
CVSS 7.3
CVE-2026-5823 MEDIUM
itsourcecode Construction Management System borrowed_tool_report.php sql injection
CVSS 6.3
CVE-2026-5814 HIGH
PHPGurukul Online Course Registration check_availability.php sql injection
CVSS 7.3
CVE-2026-5813 HIGH
PHPGurukul Online Course Registration check_availability.php sql injection
CVSS 7.3
CVE-2026-5805 HIGH
code-projects Easy Blog Site contact_us.php sql injection
CVSS 7.3
CVE-2026-33350 HIGH
LORIS MRI Feedback Popup - SQL Injection
CVSS 7.5
CVE-2026-3396 HIGH
WCAPF – WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection
CVSS 7.5
CVE-2026-1865 MEDIUM
User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]
CVSS 6.5
CVE-2026-39497 HIGH
WordPress FOX plugin <= 1.4.5 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39496 HIGH
WordPress YayMail plugin <= 4.3.3 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39495 HIGH
WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
CVSS 8.5
CVE-2026-39487 HIGH
WordPress Amelia plugin <= 2.1.1 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39486 HIGH
WordPress Download Monitor plugin <= 5.1.8 - SQL Injection vulnerability
CVSS 8.5
CVE-2026-39479 HIGH
WordPress OttoKit plugin <= 1.1.20 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39475 HIGH
WordPress User Feedback plugin <= 1.10.1 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39466 HIGH
WordPress Broken Link Checker plugin <= 2.4.7 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-33088 CRITICAL
Movable Type < 9.1.0, < 9.0.6, < 8.8.2, < 8.0.9 - SQL Injection
CVSS 9.8
CVE-2026-3781 MEDIUM
Attendance Manager <= 0.6.2 - Authenticated (Subscriber+) SQL Injection via 'attmgr_off' Parameter
CVSS 5.4
CVE-2026-24913 HIGH
MATCHA INVOICE <= 2.6.6 - Authenticated SQL Injection
CVSS 8.8
CVE-2026-39356 HIGH
SQL Injection via escapeName() in all Drizzle ORM SQL dialects
CVSS 7.5
CVE-2026-5736 HIGH
PowerJob detailPlus Endpoint InstanceController.java sql injection
CVSS 7.3
Details
Vulnerabilities 19,493
Exploit Likelihood High