CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,493 vulnerabilities with CWE-89
CVE-2026-39343 HIGH
ChurchCRM <7.1.0 Event Type Editor - SQL Injection
CVSS 7.2
CVE-2026-39342 HIGH
ChurchCRM <7.1.0 QueryView.php searchwhat - SQL Injection
CVSS 8.8
CVE-2026-39341 HIGH
SQL injection in ChurchCRM.0
CVSS 8.1
CVE-2026-39340 HIGH
ChurchCRM <7.1.0 PropertyTypeEditor.php - SQL Injection
CVSS 8.1
CVE-2026-39334 HIGH
ChurchCRM <7.1.0 SettingsIndividual.php - Blind SQL Injection
CVSS 8.8
CVE-2026-39330 HIGH
ChurchCRM <7.1.0 PropertyAssign.php - Blind SQL Injection
CVSS 8.8
CVE-2026-39329 HIGH
ChurchCRM <7.1.0 EventNames.php - Blind SQL Injection
CVSS 8.8
CVE-2026-39327 HIGH
ChurchCRM <7.1.0 MemberRoleChange.php - SQL Injection
CVSS 8.8
CVE-2026-39326 HIGH
ChurchCRM <7.1.0 PropertyTypeEditor.php - Blind SQL Injection
CVSS 8.8
CVE-2026-39325 HIGH
ChurchCRM <7.1.0 SettingsUser.php - Blind SQL Injection
CVSS 7.2
CVE-2026-39319 HIGH
ChurchCRM <7.1.0 FundRaiserEditor.php - Second-Order SQL Injection
CVSS 8.8
CVE-2026-39318 HIGH
ChurchCRM <7.1.0 Custom Field Row Operations - SQL Injection
CVSS 8.8
CVE-2026-35614 CRITICAL
Frappe bulk_update - SQL Injection
CVSS 9.8
CVE-2026-23696 CRITICAL
Windmill < 1.603.3 File Ownership Handling SQLi RCE
CVSS 9.9
CVE-2026-5372 MEDIUM
runZero Platform SQL injection in saved queries
CVSS 6.4
CVE-2026-4079 MEDIUM
SQL Chart Builder < 2.3.8 - Unauthenticated SQL Injection
CVSS 6.5
CVE-2026-5719 MEDIUM
itsourcecode Construction Management System borrowedtool.php sql injection
CVSS 6.3
CVE-2026-35395 HIGH
WeGIA <3.6.9 DespachoDAO.php id_memorando - SQL Injection
CVSS 8.8
CVE-2026-5681 MEDIUM
itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection
CVSS 6.3
CVE-2026-35184 CRITICAL
EcclesiaCRM <8.0.0 queryview.php - SQL Injection
CVSS 9.8
CVE-2026-5675 MEDIUM
itsourcecode Construction Management System Parameter borrowed_tool.php sql injection
CVSS 6.3
CVE-2026-5672 HIGH
code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection
CVSS 7.3
CVE-2026-35470 HIGH
OpenSTAManager <2.10.2 confronta_righe.php - SQL Injection
CVSS 8.8
CVE-2026-5669 HIGH
Cyber-III Student-Management-System Parameter login.php sql injection
CVSS 7.3
CVE-2026-5665 HIGH
code-projects Online FIR System Login checklogin.php sql injection
CVSS 7.3
Details
Vulnerabilities 19,493
Exploit Likelihood High