CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,493 vulnerabilities with CWE-89
CVE-2026-39343
HIGH
ChurchCRM <7.1.0 Event Type Editor - SQL Injection
CVSS 7.2
CVE-2026-39342
HIGH
ChurchCRM <7.1.0 QueryView.php searchwhat - SQL Injection
CVSS 8.8
CVE-2026-39341
HIGH
SQL injection in ChurchCRM.0
CVSS 8.1
CVE-2026-39340
HIGH
ChurchCRM <7.1.0 PropertyTypeEditor.php - SQL Injection
CVSS 8.1
CVE-2026-39334
HIGH
ChurchCRM <7.1.0 SettingsIndividual.php - Blind SQL Injection
CVSS 8.8
CVE-2026-39330
HIGH
ChurchCRM <7.1.0 PropertyAssign.php - Blind SQL Injection
CVSS 8.8
CVE-2026-39329
HIGH
ChurchCRM <7.1.0 EventNames.php - Blind SQL Injection
CVSS 8.8
CVE-2026-39327
HIGH
ChurchCRM <7.1.0 MemberRoleChange.php - SQL Injection
CVSS 8.8
CVE-2026-39326
HIGH
ChurchCRM <7.1.0 PropertyTypeEditor.php - Blind SQL Injection
CVSS 8.8
CVE-2026-39325
HIGH
ChurchCRM <7.1.0 SettingsUser.php - Blind SQL Injection
CVSS 7.2
CVE-2026-39319
HIGH
ChurchCRM <7.1.0 FundRaiserEditor.php - Second-Order SQL Injection
CVSS 8.8
CVE-2026-39318
HIGH
ChurchCRM <7.1.0 Custom Field Row Operations - SQL Injection
CVSS 8.8
CVE-2026-35614
CRITICAL
Frappe bulk_update - SQL Injection
CVSS 9.8
CVE-2026-23696
CRITICAL
Windmill < 1.603.3 File Ownership Handling SQLi RCE
CVSS 9.9
CVE-2026-5372
MEDIUM
runZero Platform SQL injection in saved queries
CVSS 6.4
CVE-2026-4079
MEDIUM
SQL Chart Builder < 2.3.8 - Unauthenticated SQL Injection
CVSS 6.5
CVE-2026-5719
MEDIUM
itsourcecode Construction Management System borrowedtool.php sql injection
CVSS 6.3
CVE-2026-35395
HIGH
WeGIA <3.6.9 DespachoDAO.php id_memorando - SQL Injection
CVSS 8.8
CVE-2026-5681
MEDIUM
itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection
CVSS 6.3
CVE-2026-35184
CRITICAL
EcclesiaCRM <8.0.0 queryview.php - SQL Injection
CVSS 9.8
CVE-2026-5675
MEDIUM
itsourcecode Construction Management System Parameter borrowed_tool.php sql injection
CVSS 6.3
CVE-2026-5672
HIGH
code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection
CVSS 7.3
CVE-2026-35470
HIGH
OpenSTAManager <2.10.2 confronta_righe.php - SQL Injection
CVSS 8.8
CVE-2026-5669
HIGH
Cyber-III Student-Management-System Parameter login.php sql injection
CVSS 7.3
CVE-2026-5665
HIGH
code-projects Online FIR System Login checklogin.php sql injection
CVSS 7.3
Details
Vulnerabilities
19,493
Exploit Likelihood
High