CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,493 vulnerabilities with CWE-89
CVE-2026-34885
HIGH
WordPress Media LIbrary Assistant plugin <= 3.34 - SQL Injection vulnerability
CVSS 8.5
CVE-2026-29047
HIGH
GLPI 10.0.0-10.0.23 and 11.0.x Log Exports - Authenticated SQL Injection
CVSS 7.2
CVE-2026-26263
HIGH
GLPI 11.0.0-11.0.5 Search Engine - Unauthenticated SQL Injection
CVSS 8.1
CVE-2026-5660
MEDIUM
itsourcecode Construction Management System Parameter borrowed_equip.php sql injection
CVSS 6.3
CVE-2026-5649
MEDIUM
code-projects Online Application System for Admission Endpoint admsnform.php sql injection
CVSS 6.3
CVE-2026-5648
HIGH
code-projects Simple Laundry System Parameter userfinishregister.php sql injection
CVSS 7.3
CVE-2026-5646
HIGH
code-projects Easy Blog Site login.php sql injection
CVSS 7.3
CVE-2026-5645
HIGH
projectworlds Car Rental System Parameter pay.php sql injection
CVSS 7.3
CVE-2026-5641
MEDIUM
PHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injection
CVSS 6.3
CVE-2026-5640
MEDIUM
PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection
CVSS 6.3
CVE-2026-5639
MEDIUM
PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection
CVSS 6.3
CVE-2026-5637
HIGH
projectworlds Car Rental System Parameter message_admin.php sql injection
CVSS 7.3
CVE-2026-5636
MEDIUM
PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection
CVSS 6.3
CVE-2026-5635
MEDIUM
PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection
CVSS 6.3
CVE-2026-5634
HIGH
projectworlds Car Rental Project Parameter book_car.php sql injection
CVSS 7.3
CVE-2026-5620
MEDIUM
itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection
CVSS 6.3
CVE-2026-5606
MEDIUM
PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection
CVSS 6.3
CVE-2026-5596
MEDIUM
griptape-ai griptape SqlTool tool.py sql injection
CVSS 6.3
CVE-2026-5587
MEDIUM
wbbeyourself MAC-SQL Refiner Agent agents.py _execute_sql sql injection
CVSS 6.3
CVE-2026-5586
MEDIUM
zhongyu09 openchatbi Multi-stage Text2SQL Workflow sql injection
CVSS 6.3
CVE-2026-5583
MEDIUM
PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection
CVSS 6.3
CVE-2026-5580
MEDIUM
CodeAstro Online Classroom Parameter addvideos.php sql injection
CVSS 6.3
CVE-2026-5579
MEDIUM
CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection
CVSS 6.3
CVE-2026-5578
MEDIUM
CodeAstro Online Classroom Parameter addassessment.php sql injection
CVSS 6.3
CVE-2026-5577
HIGH
Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection
CVSS 7.3
Details
Vulnerabilities
19,493
Exploit Likelihood
High