CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,493 vulnerabilities with CWE-89
CVE-2026-5195 HIGH
code-projects Student Membership System User Registration sql injection
CVSS 7.3
CVE-2026-5182 HIGH
SourceCodester Teacher Record System Parameter sql injection
CVSS 7.3
CVE-2026-5180 HIGH
SourceCodester Simple Doctors Appointment System ajax.php sql injection
CVSS 7.3
CVE-2026-5179 HIGH
SourceCodester Simple Doctors Appointment System login.php sql injection
CVSS 7.3
CVE-2026-32714 CRITICAL
SciTokens vulnerable to SQL Injection in KeyCache
CVSS 9.8
CVE-2026-27697 CRITICAL
baserCMS: SQL injection vulnerability in blog post
CVSS 9.8
CVE-2026-5150 HIGH
code-projects Accounting System Parameter viewin_costumer.php sql injection
CVSS 7.3
CVE-2026-5148 MEDIUM
YunaiV yudao-cloud page sql injection
CVSS 4.7
CVE-2026-31799 MEDIUM
Tautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parameters
CVSS 4.9
CVE-2026-5147 HIGH
YunaiV yudao-cloud get-by-website sql injection
CVSS 7.3
CVE-2026-33643 HIGH
schemahero/schemahero < 0.23.0 - SQL Injection via mysqlColumnAsInsert Column Parameter
CVSS 7.4
CVE-2026-29953 HIGH
schemahero/schemahero < 0.23.0 - SQL Injection via column Parameter
CVSS 7.4
CVE-2026-5035 HIGH
code-projects Accounting System Parameter view_work.php sql injection
CVSS 7.3
CVE-2026-5034 HIGH
code-projects Accounting System Parameter edit_costumer.php sql injection
CVSS 7.3
CVE-2026-5033 HIGH
code-projects Accounting System Parameter view_costumer.php sql injection
CVSS 7.3
CVE-2026-5019 HIGH
code-projects Simple Food Order System Parameter all-orders.php sql injection
CVSS 7.3
CVE-2026-5018 HIGH
code-projects Simple Food Order System Parameter register-router.php sql injection
CVSS 7.3
CVE-2026-5017 HIGH
code-projects Simple Food Order System Parameter all-tickets.php sql injection
CVSS 7.3
CVE-2026-4996 HIGH
Sinaptik AI PandasAI pandasai-lancedb Extension lancedb.py get_relevant_docs_by_id sql injection
CVSS 7.3
CVE-2026-33991 HIGH
WeGIA has SQL Injection in deletar_tag.php
CVSS 8.8
CVE-2026-4970 MEDIUM
code-projects Social Networking Site Endpoint delete_photos.php sql injection
CVSS 6.3
CVE-2026-34386 HIGH
Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global admin
CVSS 8.8
CVE-2026-34385 HIGH
Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the database
CVSS 8.1
CVE-2026-34374 CRITICAL
AVideo has SQL Injection in Live_schedule::keyExists() via Unparameterized Stream Key
CVSS 9.1
CVE-2026-4966 MEDIUM
itsourcecode Free Hotel Reservation System index.php sql injection
CVSS 6.3
Details
Vulnerabilities 19,493
Exploit Likelihood High