CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,493 vulnerabilities with CWE-89
CVE-2026-5195
HIGH
code-projects Student Membership System User Registration sql injection
CVSS 7.3
CVE-2026-5182
HIGH
SourceCodester Teacher Record System Parameter sql injection
CVSS 7.3
CVE-2026-5180
HIGH
SourceCodester Simple Doctors Appointment System ajax.php sql injection
CVSS 7.3
CVE-2026-5179
HIGH
SourceCodester Simple Doctors Appointment System login.php sql injection
CVSS 7.3
CVE-2026-32714
CRITICAL
SciTokens vulnerable to SQL Injection in KeyCache
CVSS 9.8
CVE-2026-27697
CRITICAL
baserCMS: SQL injection vulnerability in blog post
CVSS 9.8
CVE-2026-5150
HIGH
code-projects Accounting System Parameter viewin_costumer.php sql injection
CVSS 7.3
CVE-2026-5148
MEDIUM
YunaiV yudao-cloud page sql injection
CVSS 4.7
CVE-2026-31799
MEDIUM
Tautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parameters
CVSS 4.9
CVE-2026-5147
HIGH
YunaiV yudao-cloud get-by-website sql injection
CVSS 7.3
CVE-2026-33643
HIGH
schemahero/schemahero < 0.23.0 - SQL Injection via mysqlColumnAsInsert Column Parameter
CVSS 7.4
CVE-2026-29953
HIGH
schemahero/schemahero < 0.23.0 - SQL Injection via column Parameter
CVSS 7.4
CVE-2026-5035
HIGH
code-projects Accounting System Parameter view_work.php sql injection
CVSS 7.3
CVE-2026-5034
HIGH
code-projects Accounting System Parameter edit_costumer.php sql injection
CVSS 7.3
CVE-2026-5033
HIGH
code-projects Accounting System Parameter view_costumer.php sql injection
CVSS 7.3
CVE-2026-5019
HIGH
code-projects Simple Food Order System Parameter all-orders.php sql injection
CVSS 7.3
CVE-2026-5018
HIGH
code-projects Simple Food Order System Parameter register-router.php sql injection
CVSS 7.3
CVE-2026-5017
HIGH
code-projects Simple Food Order System Parameter all-tickets.php sql injection
CVSS 7.3
CVE-2026-4996
HIGH
Sinaptik AI PandasAI pandasai-lancedb Extension lancedb.py get_relevant_docs_by_id sql injection
CVSS 7.3
CVE-2026-33991
HIGH
WeGIA has SQL Injection in deletar_tag.php
CVSS 8.8
CVE-2026-4970
MEDIUM
code-projects Social Networking Site Endpoint delete_photos.php sql injection
CVSS 6.3
CVE-2026-34386
HIGH
Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global admin
CVSS 8.8
CVE-2026-34385
HIGH
Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the database
CVSS 8.1
CVE-2026-34374
CRITICAL
AVideo has SQL Injection in Live_schedule::keyExists() via Unparameterized Stream Key
CVSS 9.1
CVE-2026-4966
MEDIUM
itsourcecode Free Hotel Reservation System index.php sql injection
CVSS 6.3
Details
Vulnerabilities
19,493
Exploit Likelihood
High