CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,501 vulnerabilities with CWE-89
CVE-2026-26705 CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26704 CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-28399 HIGH
NocoDB < 0.301.3 - Authenticated SQL Injection via DATEADD Formula Unit Parameter
CVSS 8.8
CVE-2026-26708 CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26700 CRITICAL
sourcecodester PPES 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26701 CRITICAL
Personnel Property Equipment System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26703 CRITICAL
Personnel Property Equipment System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26702 CRITICAL
Personnel Property Equipment System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26696 CRITICAL
Simple Student Alumni System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26695 CRITICAL
Simple Student Alumni System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26694 CRITICAL
Simple Student Alumni System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26698 MEDIUM
Simple Student Alumni System 1.0 - SQL Injection
CVSS 4.9
CVE-2026-26697 MEDIUM
Simple Student Alumni System 1.0 - SQL Injection
CVSS 4.9
CVE-2026-2584 CRITICAL
CISER System Firmware Authentication Module - SQL Injection
CVE-2026-3413 HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3411 HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3410 HIGH
itsourcecode Society Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3406 HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-28562 HIGH
wpForo Forum 2.4.0-2.4.14 - Unauthenticated SQL Injection via Topics ORDER BY Parameter
CVSS 8.2
CVE-2026-28516 HIGH
openDCIM < 23.04 - Authenticated SQL Injection via Config::UpdateParameter
CVSS 8.8
CVE-2026-27832 HIGH
Group-Office <26.0.8 - SQL Injection
CVSS 8.8
CVE-2026-2751 HIGH
Centreon Web <25.10.8 - Blind SQL Injection
CVSS 8.3
CVE-2026-2831 MEDIUM
MailArchiver Plugin <4.5.0 - SQL Injection
CVSS 4.9
CVE-2026-3292 MEDIUM
jizhicms < 2.5.6 - SQL Injection via Batch Interface findAll Function
CVSS 6.3
CVE-2026-3287 MEDIUM
youlai-mall 2.0.0 - SQL Injection via App-side Product Pagination Endpoint
CVSS 6.3
Details
Vulnerabilities 19,501
Exploit Likelihood High