CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,493 vulnerabilities with CWE-89
CVE-2026-5334
HIGH
itsourcecode Online Enrollment System Parameter index.php sql injection
CVSS 7.3
CVE-2026-35168
HIGH
OpenSTAManager: SQL Injection via Aggiornamenti Module
CVSS 8.8
CVE-2026-28805
HIGH
OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter
CVSS 8.8
CVE-2026-5328
MEDIUM
shsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection
CVSS 6.3
CVE-2026-33616
HIGH
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api Endpoint
CVSS 7.5
CVE-2026-33615
CRITICAL
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo Endpoint
CVSS 9.1
CVE-2026-33614
HIGH
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo endpoint
CVSS 7.5
CVE-2026-5322
HIGH
AlejandroArciniegas mcp-data-vis MCP server.js request sql injection
CVSS 7.3
CVE-2026-34747
HIGH
Payload <3.79.1 Query Handling - SQL Injection
CVSS 8.5
CVE-2026-34455
HIGH
Hi.Events: SQL Injection via Unvalidated sort_by Query Parameter in Multiple Repository Classes
CVSS 8.8
CVE-2026-30273
HIGH
pandasai < 3.0.0 - SQL Injection via pandasai.agent.base._execute_sql_query
CVSS 7.3
CVE-2026-21630
HIGH
Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint
CVSS 8.8
CVE-2026-5257
HIGH
code-projects Simple Laundry System Parameter delstaffinfo.php sql injection
CVSS 7.3
CVE-2026-5256
HIGH
code-projects Simple Laundry System Parameter modify.php sql injection
CVSS 7.3
CVE-2026-5238
HIGH
itsourcecode Payroll Management System Parameter view_employee.php sql injection
CVSS 7.3
CVE-2026-4668
MEDIUM
Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter
CVSS 6.5
CVE-2026-5237
HIGH
itsourcecode Payroll Management System Parameter manage_user.php sql injection
CVSS 7.3
CVE-2026-34400
CRITICAL
alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
CVSS 9.8
CVE-2026-5206
MEDIUM
code-projects Simple Gym Management System Payment sql injection
CVSS 6.3
CVE-2026-30520
MEDIUM
SourceCodester Loan Management System 1.0 - SQL Injection
CVSS 5.4
CVE-2026-34220
CRITICAL
MikroORM is vulnerable to SQL Injection via specially crafted object
CVSS 9.8
CVE-2026-5198
HIGH
code-projects Student Membership System Admin Login index.php sql injection
CVSS 7.3
CVE-2026-5197
MEDIUM
code-projects Student Membership System delete_user.php sql injection
CVSS 6.3
CVE-2026-4317
CRITICAL
SQL inyection in Umami Software application
CVE-2026-5196
MEDIUM
code-projects Student Membership System delete_member.php sql injection
CVSS 6.3
Details
Vulnerabilities
19,493
Exploit Likelihood
High