CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,493 vulnerabilities with CWE-89
CVE-2026-5334 HIGH
itsourcecode Online Enrollment System Parameter index.php sql injection
CVSS 7.3
CVE-2026-35168 HIGH
OpenSTAManager: SQL Injection via Aggiornamenti Module
CVSS 8.8
CVE-2026-28805 HIGH
OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter
CVSS 8.8
CVE-2026-5328 MEDIUM
shsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection
CVSS 6.3
CVE-2026-33616 HIGH
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api Endpoint
CVSS 7.5
CVE-2026-33615 CRITICAL
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo Endpoint
CVSS 9.1
CVE-2026-33614 HIGH
MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo endpoint
CVSS 7.5
CVE-2026-5322 HIGH
AlejandroArciniegas mcp-data-vis MCP server.js request sql injection
CVSS 7.3
CVE-2026-34747 HIGH
Payload <3.79.1 Query Handling - SQL Injection
CVSS 8.5
CVE-2026-34455 HIGH
Hi.Events: SQL Injection via Unvalidated sort_by Query Parameter in Multiple Repository Classes
CVSS 8.8
CVE-2026-30273 HIGH
pandasai < 3.0.0 - SQL Injection via pandasai.agent.base._execute_sql_query
CVSS 7.3
CVE-2026-21630 HIGH
Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint
CVSS 8.8
CVE-2026-5257 HIGH
code-projects Simple Laundry System Parameter delstaffinfo.php sql injection
CVSS 7.3
CVE-2026-5256 HIGH
code-projects Simple Laundry System Parameter modify.php sql injection
CVSS 7.3
CVE-2026-5238 HIGH
itsourcecode Payroll Management System Parameter view_employee.php sql injection
CVSS 7.3
CVE-2026-4668 MEDIUM
Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter
CVSS 6.5
CVE-2026-5237 HIGH
itsourcecode Payroll Management System Parameter manage_user.php sql injection
CVSS 7.3
CVE-2026-34400 CRITICAL
alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
CVSS 9.8
CVE-2026-5206 MEDIUM
code-projects Simple Gym Management System Payment sql injection
CVSS 6.3
CVE-2026-30520 MEDIUM
SourceCodester Loan Management System 1.0 - SQL Injection
CVSS 5.4
CVE-2026-34220 CRITICAL
MikroORM is vulnerable to SQL Injection via specially crafted object
CVSS 9.8
CVE-2026-5198 HIGH
code-projects Student Membership System Admin Login index.php sql injection
CVSS 7.3
CVE-2026-5197 MEDIUM
code-projects Student Membership System delete_user.php sql injection
CVSS 6.3
CVE-2026-4317 CRITICAL
SQL inyection in Umami Software application
CVE-2026-5196 MEDIUM
code-projects Student Membership System delete_member.php sql injection
CVSS 6.3
Details
Vulnerabilities 19,493
Exploit Likelihood High