CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,493 vulnerabilities with CWE-89
CVE-2026-4306 HIGH
WP Job Portal Plugin for WordPress <=2.4.8 - SQL Injection
CVSS 7.5
CVE-2026-2412 MEDIUM
Quiz and Survey Master 10.3.5 - SQL Injection
CVSS 6.5
CVE-2026-4612 HIGH
itsourcecode Free Hotel Reservation System Parameter index.php sql injection
CVSS 7.3
CVE-2026-4597 MEDIUM
648540858 wvp-GB28181-pro Stream Proxy Query StreamProxyProvider.java selectAll sql injection
CVSS 6.3
CVE-2026-33723 HIGH
AVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subscribe.php
CVSS 7.1
CVE-2026-33651 HIGH
AVideo <=26.0 Live Schedule Reminder - Blind SQL Injection
CVSS 8.1
CVE-2026-4594 HIGH
erupts erupt EruptJpaUtils.java geneEruptHqlOrderBy sql injection
CVSS 7.3
CVE-2026-4593 MEDIUM
erupts erupt MCP Tool EruptDataQuery.java EruptDataQuery sql injection
CVSS 6.3
CVE-2026-33485 HIGH
AVideo <=26.0 RTMP on_publish - Unauthenticated Blind SQL Injection
CVSS 7.5
CVE-2026-33352 CRITICAL
AVideo <26.0 doNotShowCats - Unauthenticated SQL Injection
CVSS 9.8
CVE-2026-32969 HIGH
Pre-Auth Blind SQLi in userinfo Endpoint
CVSS 7.5
CVE-2026-4581 HIGH
code-projects Simple Laundry System Parameters checklogin.php sql injection
CVSS 7.3
CVE-2026-4580 HIGH
code-projects Simple Laundry System Parameters checkupdatestatus.php sql injection
CVSS 7.3
CVE-2026-4579 HIGH
code-projects Simple Laundry System Parameters viewdetail.php sql injection
CVSS 7.3
CVE-2026-4574 MEDIUM
SourceCodester Simple E-learning System User Profile Update sql injection
CVSS 6.3
CVE-2026-4573 MEDIUM
SourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injection
CVSS 6.3
CVE-2026-4572 MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection
CVSS 6.3
CVE-2026-4571 MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection
CVSS 6.3
CVE-2026-4570 MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql injection
CVSS 6.3
CVE-2026-4569 MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection
CVSS 6.3
CVE-2026-4568 MEDIUM
SourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql injection
CVSS 6.3
CVE-2026-2580 HIGH
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter
CVSS 7.5
CVE-2026-4550 MEDIUM
code-projects Simple Gym Management System func.php sql injection
CVSS 4.7
CVE-2026-4540 HIGH
projectworlds Online Notes Sharing System Parameters login.php sql injection
CVSS 7.3
CVE-2026-4533 MEDIUM
code-projects Simple Food Ordering System all-tickets.php sql injection
CVSS 6.3
Details
Vulnerabilities 19,493
Exploit Likelihood High