CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,493 vulnerabilities with CWE-89
CVE-2026-4306
HIGH
WP Job Portal Plugin for WordPress <=2.4.8 - SQL Injection
CVSS 7.5
CVE-2026-2412
MEDIUM
Quiz and Survey Master 10.3.5 - SQL Injection
CVSS 6.5
CVE-2026-4612
HIGH
itsourcecode Free Hotel Reservation System Parameter index.php sql injection
CVSS 7.3
CVE-2026-4597
MEDIUM
648540858 wvp-GB28181-pro Stream Proxy Query StreamProxyProvider.java selectAll sql injection
CVSS 6.3
CVE-2026-33723
HIGH
AVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subscribe.php
CVSS 7.1
CVE-2026-33651
HIGH
AVideo <=26.0 Live Schedule Reminder - Blind SQL Injection
CVSS 8.1
CVE-2026-4594
HIGH
erupts erupt EruptJpaUtils.java geneEruptHqlOrderBy sql injection
CVSS 7.3
CVE-2026-4593
MEDIUM
erupts erupt MCP Tool EruptDataQuery.java EruptDataQuery sql injection
CVSS 6.3
CVE-2026-33485
HIGH
AVideo <=26.0 RTMP on_publish - Unauthenticated Blind SQL Injection
CVSS 7.5
CVE-2026-33352
CRITICAL
AVideo <26.0 doNotShowCats - Unauthenticated SQL Injection
CVSS 9.8
CVE-2026-32969
HIGH
Pre-Auth Blind SQLi in userinfo Endpoint
CVSS 7.5
CVE-2026-4581
HIGH
code-projects Simple Laundry System Parameters checklogin.php sql injection
CVSS 7.3
CVE-2026-4580
HIGH
code-projects Simple Laundry System Parameters checkupdatestatus.php sql injection
CVSS 7.3
CVE-2026-4579
HIGH
code-projects Simple Laundry System Parameters viewdetail.php sql injection
CVSS 7.3
CVE-2026-4574
MEDIUM
SourceCodester Simple E-learning System User Profile Update sql injection
CVSS 6.3
CVE-2026-4573
MEDIUM
SourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injection
CVSS 6.3
CVE-2026-4572
MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection
CVSS 6.3
CVE-2026-4571
MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection
CVSS 6.3
CVE-2026-4570
MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql injection
CVSS 6.3
CVE-2026-4569
MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection
CVSS 6.3
CVE-2026-4568
MEDIUM
SourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql injection
CVSS 6.3
CVE-2026-2580
HIGH
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter
CVSS 7.5
CVE-2026-4550
MEDIUM
code-projects Simple Gym Management System func.php sql injection
CVSS 4.7
CVE-2026-4540
HIGH
projectworlds Online Notes Sharing System Parameters login.php sql injection
CVSS 7.3
CVE-2026-4533
MEDIUM
code-projects Simple Food Ordering System all-tickets.php sql injection
CVSS 6.3
Details
Vulnerabilities
19,493
Exploit Likelihood
High