CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,497 vulnerabilities with CWE-89
CVE-2026-3487 MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2026-3486 MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2026-26892 HIGH
Sourcecodester Logistic Hub 1.0 - SQL Injection
CVSS 7.2
CVE-2026-26891 LOW
Logistic Hub Parcel's Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-26889 LOW
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-26888 LOW
Sourcecodester Pharmacy POS 1.0 - SQL Injection
CVSS 2.7
CVE-2026-26887 LOW
Sourcecodester Pharmacy POS 1.0 - SQL Injection
CVSS 2.7
CVE-2026-26890 LOW
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-26886 LOW
Online Men's Salon Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-26885 LOW
Online Men's Salon Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-26884 LOW
Online Men's Salon Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-26883 LOW
Online Men's Salon Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-1487 MEDIUM
LatePoint Calendar Booking Plugin <5.2.7 - SQL Injection
CVSS 6.5
CVE-2026-26713 CRITICAL
Simple Food Order System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26712 CRITICAL
Simple Food Order System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26711 CRITICAL
Simple Food Order System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26710 CRITICAL
Simple Food Order System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26709 CRITICAL
Simple Gym Management System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-3180 HIGH
Contest Gallery Plugin <28.1.4 - SQL Injection
CVSS 7.5
CVE-2026-26707 CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26706 CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26705 CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26704 CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-28399 HIGH
NocoDB < 0.301.3 - Authenticated SQL Injection via DATEADD Formula Unit Parameter
CVSS 8.8
CVE-2026-26708 CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
Details
Vulnerabilities 19,497
Exploit Likelihood High