CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,493 vulnerabilities with CWE-89
CVE-2026-33770 CRITICAL
AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Variables
CVSS 9.8
CVE-2026-33767 HIGH
AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into Query
CVSS 8.8
CVE-2026-30534 HIGH
SourceCodester Online Food Ordering System 1.0 - SQL Injection
CVSS 8.3
CVE-2026-30533 CRITICAL
SourceCodester Online Food Ordering System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-30532 CRITICAL
SourceCodester Online Food Ordering System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-30531 HIGH
SourceCodester Online Food Ordering System 1.0 - SQL Injection
CVSS 8.8
CVE-2026-30530 CRITICAL
SourceCodester Online Food Ordering System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-30529 HIGH
SourceCodester Online Food Ordering System 1.0 - SQL Injection
CVSS 8.8
CVE-2026-4956 HIGH
Shenzhen Ruiming Technology Streamax Crocus Parameter DevicePrint.do sql injection
CVSS 7.3
CVE-2026-4955 HIGH
Shenzhen Ruiming Technology Streamax Crocus OperateStatistic.do sql injection
CVSS 7.3
CVE-2026-4954 MEDIUM
mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection
CVSS 6.3
CVE-2026-33755 HIGH
Authenticated SQL Injection in Contact/query addressBookIds filter
CVSS 8.8
CVE-2026-24031 HIGH
OX Dovecot Pro <3.1.0 - Auth Bypass
CVSS 7.7
CVE-2026-22743 HIGH
Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore
CVSS 7.5
CVE-2026-4910 HIGH
Shenzhen Ruiming Technology Streamax Crocus Endpoint RemoteFormat.do sql injection
CVSS 7.3
CVE-2026-4908 HIGH
code-projects Simple Laundry System Parameter modstaffinfo.php sql injection
CVSS 7.3
CVE-2026-33545 MEDIUM
MobSF has SQL Injection in its SQLite Database Viewer Utils
CVSS 5.3
CVE-2026-33531 MEDIUM
InvenTree has Path Traversal In Report Templates
CVSS 6.5
CVE-2026-33505 HIGH
Ory Keto <26.2.0 Pagination Tokens - SQL Injection
CVSS 7.2
CVE-2026-33153 MEDIUM
Tandoor Recipes's Unauthenticated Debug Parameter Leaks Full Raw SQL Queries Including Schema, Table Names, and Access Control Logic
CVSS 6.5
CVE-2026-30463 HIGH
FuelCMS 1.5.2 - SQL Injection via Login Controller
CVSS 7.7
CVE-2026-33504 HIGH
Ory Hydra <26.2.0 Pagination Tokens - SQL Injection
CVSS 7.2
CVE-2026-33503 HIGH
Ory Kratos <26.2.0 Pagination Tokens - SQL Injection
CVSS 7.2
CVE-2026-33468 HIGH
Kysely <0.28.14 MySQL String Literals - SQL Injection
CVSS 8.1
CVE-2026-33442 HIGH
Kysely 0.28.12-0.28.13 MySQL JSON Path Keys - SQL Injection
CVSS 8.1
Details
Vulnerabilities 19,493
Exploit Likelihood High