CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,501 vulnerabilities with CWE-89
CVE-2026-26705
CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26704
CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-28399
HIGH
NocoDB < 0.301.3 - Authenticated SQL Injection via DATEADD Formula Unit Parameter
CVSS 8.8
CVE-2026-26708
CRITICAL
Pharmacy Point of Sale System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26700
CRITICAL
sourcecodester PPES 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26701
CRITICAL
Personnel Property Equipment System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26703
CRITICAL
Personnel Property Equipment System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26702
CRITICAL
Personnel Property Equipment System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26696
CRITICAL
Simple Student Alumni System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26695
CRITICAL
Simple Student Alumni System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26694
CRITICAL
Simple Student Alumni System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-26698
MEDIUM
Simple Student Alumni System 1.0 - SQL Injection
CVSS 4.9
CVE-2026-26697
MEDIUM
Simple Student Alumni System 1.0 - SQL Injection
CVSS 4.9
CVE-2026-2584
CRITICAL
CISER System Firmware Authentication Module - SQL Injection
CVE-2026-3413
HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3411
HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3410
HIGH
itsourcecode Society Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3406
HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-28562
HIGH
wpForo Forum 2.4.0-2.4.14 - Unauthenticated SQL Injection via Topics ORDER BY Parameter
CVSS 8.2
CVE-2026-28516
HIGH
openDCIM < 23.04 - Authenticated SQL Injection via Config::UpdateParameter
CVSS 8.8
CVE-2026-27832
HIGH
Group-Office <26.0.8 - SQL Injection
CVSS 8.8
CVE-2026-2751
HIGH
Centreon Web <25.10.8 - Blind SQL Injection
CVSS 8.3
CVE-2026-2831
MEDIUM
MailArchiver Plugin <4.5.0 - SQL Injection
CVSS 4.9
CVE-2026-3292
MEDIUM
jizhicms < 2.5.6 - SQL Injection via Batch Interface findAll Function
CVSS 6.3
CVE-2026-3287
MEDIUM
youlai-mall 2.0.0 - SQL Injection via App-side Product Pagination Endpoint
CVSS 6.3
Details
Vulnerabilities
19,501
Exploit Likelihood
High