CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,501 vulnerabilities with CWE-89
CVE-2026-28226 MEDIUM
Phishing Club <1.30.2 - SQL Injection
CVSS 6.5
CVE-2026-3261 HIGH
itsourcecode School Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-27149 MEDIUM
Discourse <2025.12.2 - SQL Injection
CVSS 6.5
CVE-2026-22206 HIGH
SPIP < 4.4.10 - Authenticated SQL Injection and Remote Code Execution via UNION-Based Injection
CVSS 8.8
CVE-2026-1198 HIGH
Simple.ERP < [email protected]_u06 - Authenticated SQL Injection in Search Functionality
CVE-2026-28136 HIGH
VeronaLabs WP SMS <= 6.9.12 - SQL Injection
CVSS 7.6
CVE-2026-26186 HIGH
Fleet < 4.80.1 - Authenticated SQL Injection via order_key Query Parameter
CVSS 8.8
CVE-2026-27497 HIGH
n8n <2.10.1/2.9.3/1.123.22 - Code Injection
CVSS 8.8
CVE-2026-3200 HIGH
z-9527 admin 1.0/2.0 - SQL Injection
CVSS 7.3
CVE-2026-25746 HIGH
OpenEMR < 8.0.0 - Authenticated SQL Injection in Prescription Listing
CVSS 8.8
CVE-2026-24908 CRITICAL
OpenEMR < 8.0.0 - Authenticated SQL Injection via Patient REST API _sort Parameter
CVSS 9.9
CVE-2026-23627 HIGH
OpenEMR < 8.0.0 - Authenticated SQL Injection via Immunization Module Patient ID Parameter
CVSS 8.8
CVE-2026-25554 MEDIUM
OpenSIPS 3.1-3.6.3 - SQL Injection via Unverified JWT Tag Claim in auth_jwt Module
CVSS 6.5
CVE-2026-27847 CRITICAL
MR9600 1.0.4.205530/MX4200 1.0.13.210200 - SQL Injection
CVSS 9.8
CVE-2026-3118 MEDIUM
Red Hat Developer Hub - Authenticated Denial of Service via Orchestrator Plugin GraphQL Query Injection
CVSS 6.5
CVE-2026-2416 HIGH
Geo Mashup WordPress Plugin <1.13.17 - SQL Injection
CVSS 7.5
CVE-2026-3164 HIGH
itsourcecode News Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3153 HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3152 HIGH
itsourcecode College Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3151 HIGH
itsourcecode College Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3150 MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3149 MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3148 HIGH
SourceCodester Shopping Cart 1.0 - SQL Injection
CVSS 7.3
CVE-2026-27747 HIGH
SPIP interface_traduction_objets <4.3.3 - SQL Injection
CVSS 8.8
CVE-2026-27743 CRITICAL
SPIP referer_spam <1.3.0 - SQL Injection
CVSS 9.8
Details
Vulnerabilities 19,501
Exploit Likelihood High