CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,493 vulnerabilities with CWE-89
CVE-2026-5837
HIGH
PHPGurukul News Portal Project news-details.php sql injection
CVSS 7.3
CVE-2026-5829
HIGH
code-projects Simple IT Discussion Forum content.php sql injection
CVSS 7.3
CVE-2026-5828
HIGH
code-projects Simple IT Discussion Forum addcomment.php sql injection
CVSS 7.3
CVE-2026-5827
HIGH
code-projects Simple IT Discussion Forum question-function.php sql injection
CVSS 7.3
CVE-2026-5824
HIGH
code-projects Simple Laundry System userchecklogin.php sql injection
CVSS 7.3
CVE-2026-5823
MEDIUM
itsourcecode Construction Management System borrowed_tool_report.php sql injection
CVSS 6.3
CVE-2026-5814
HIGH
PHPGurukul Online Course Registration check_availability.php sql injection
CVSS 7.3
CVE-2026-5813
HIGH
PHPGurukul Online Course Registration check_availability.php sql injection
CVSS 7.3
CVE-2026-5805
HIGH
code-projects Easy Blog Site contact_us.php sql injection
CVSS 7.3
CVE-2026-33350
HIGH
LORIS MRI Feedback Popup - SQL Injection
CVSS 7.5
CVE-2026-3396
HIGH
WCAPF – WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection
CVSS 7.5
CVE-2026-1865
MEDIUM
User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]
CVSS 6.5
CVE-2026-39497
HIGH
WordPress FOX plugin <= 1.4.5 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39496
HIGH
WordPress YayMail plugin <= 4.3.3 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39495
HIGH
WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability
CVSS 8.5
CVE-2026-39487
HIGH
WordPress Amelia plugin <= 2.1.1 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39486
HIGH
WordPress Download Monitor plugin <= 5.1.8 - SQL Injection vulnerability
CVSS 8.5
CVE-2026-39479
HIGH
WordPress OttoKit plugin <= 1.1.20 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39475
HIGH
WordPress User Feedback plugin <= 1.10.1 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-39466
HIGH
WordPress Broken Link Checker plugin <= 2.4.7 - SQL Injection vulnerability
CVSS 7.6
CVE-2026-33088
CRITICAL
Movable Type < 9.1.0, < 9.0.6, < 8.8.2, < 8.0.9 - SQL Injection
CVSS 9.8
CVE-2026-3781
MEDIUM
Attendance Manager <= 0.6.2 - Authenticated (Subscriber+) SQL Injection via 'attmgr_off' Parameter
CVSS 5.4
CVE-2026-24913
HIGH
MATCHA INVOICE <= 2.6.6 - Authenticated SQL Injection
CVSS 8.8
CVE-2026-39356
HIGH
SQL Injection via escapeName() in all Drizzle ORM SQL dialects
CVSS 7.5
CVE-2026-5736
HIGH
PowerJob detailPlus Endpoint InstanceController.java sql injection
CVSS 7.3
Details
Vulnerabilities
19,493
Exploit Likelihood
High