CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,497 vulnerabilities with CWE-89
CVE-2026-3771 MEDIUM
janobe Resort Reservation System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3767 MEDIUM
itsourcecode sanitize 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3765 HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3760 HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3759 HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3758 HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3757 HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3756 MEDIUM
SourceCodester Sales and Inventory System <1.0 - SQL Injection
CVSS 6.3
CVE-2026-3755 MEDIUM
SourceCodester Sales and Inventory System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3754 MEDIUM
SourceCodester Sales and Inventory System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3753 MEDIUM
SourceCodester Sales and Inventory System <1.0 - SQL Injection
CVSS 6.3
CVE-2026-3752 MEDIUM
SourceCodester Employee Task Management System <1.0 - SQL Injection
CVSS 4.7
CVE-2026-3751 MEDIUM
SourceCodester Employee Task Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2026-3747 HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3746 HIGH
SourceCodester Tourism Website 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3745 MEDIUM
Student Web Portal 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3744 HIGH
Student Web Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3740 HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3736 HIGH
Simple Flight Ticket Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3735 HIGH
Simple Flight Ticket Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3730 HIGH
Free Hotel Reservation System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3723 HIGH
Simple Flight Ticket Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3711 MEDIUM
Simple Flight Ticket Booking System 1.0 - SQL Injection
CVSS 4.7
CVE-2026-3710 MEDIUM
Simple Flight Ticket Booking System 1.0 - SQL Injection
CVSS 4.7
CVE-2026-3709 HIGH
Simple Flight Ticket Booking System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,497
Exploit Likelihood High