CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,493 vulnerabilities with CWE-89
CVE-2026-34885 HIGH
WordPress Media LIbrary Assistant plugin <= 3.34 - SQL Injection vulnerability
CVSS 8.5
CVE-2026-29047 HIGH
GLPI 10.0.0-10.0.23 and 11.0.x Log Exports - Authenticated SQL Injection
CVSS 7.2
CVE-2026-26263 HIGH
GLPI 11.0.0-11.0.5 Search Engine - Unauthenticated SQL Injection
CVSS 8.1
CVE-2026-5660 MEDIUM
itsourcecode Construction Management System Parameter borrowed_equip.php sql injection
CVSS 6.3
CVE-2026-5649 MEDIUM
code-projects Online Application System for Admission Endpoint admsnform.php sql injection
CVSS 6.3
CVE-2026-5648 HIGH
code-projects Simple Laundry System Parameter userfinishregister.php sql injection
CVSS 7.3
CVE-2026-5646 HIGH
code-projects Easy Blog Site login.php sql injection
CVSS 7.3
CVE-2026-5645 HIGH
projectworlds Car Rental System Parameter pay.php sql injection
CVSS 7.3
CVE-2026-5641 MEDIUM
PHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injection
CVSS 6.3
CVE-2026-5640 MEDIUM
PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection
CVSS 6.3
CVE-2026-5639 MEDIUM
PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection
CVSS 6.3
CVE-2026-5637 HIGH
projectworlds Car Rental System Parameter message_admin.php sql injection
CVSS 7.3
CVE-2026-5636 MEDIUM
PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection
CVSS 6.3
CVE-2026-5635 MEDIUM
PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection
CVSS 6.3
CVE-2026-5634 HIGH
projectworlds Car Rental Project Parameter book_car.php sql injection
CVSS 7.3
CVE-2026-5620 MEDIUM
itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection
CVSS 6.3
CVE-2026-5606 MEDIUM
PHPGurukul Online Shopping Portal Project Parameter order-details.php sql injection
CVSS 6.3
CVE-2026-5596 MEDIUM
griptape-ai griptape SqlTool tool.py sql injection
CVSS 6.3
CVE-2026-5587 MEDIUM
wbbeyourself MAC-SQL Refiner Agent agents.py _execute_sql sql injection
CVSS 6.3
CVE-2026-5586 MEDIUM
zhongyu09 openchatbi Multi-stage Text2SQL Workflow sql injection
CVSS 6.3
CVE-2026-5583 MEDIUM
PHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection
CVSS 6.3
CVE-2026-5580 MEDIUM
CodeAstro Online Classroom Parameter addvideos.php sql injection
CVSS 6.3
CVE-2026-5579 MEDIUM
CodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection
CVSS 6.3
CVE-2026-5578 MEDIUM
CodeAstro Online Classroom Parameter addassessment.php sql injection
CVSS 6.3
CVE-2026-5577 HIGH
Song-Li cross_browser details Endpoint uniquemachine_app.py sql injection
CVSS 7.3
Details
Vulnerabilities 19,493
Exploit Likelihood High