CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,501 vulnerabilities with CWE-89
CVE-2026-3135 HIGH
itsourcecode News Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3134 HIGH
itsourcecode News Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3133 HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-21410 CRITICAL
InSAT MasterSCADA BUK-TS - SQL Injection
CVSS 9.8
CVE-2026-3105 HIGH
Mautic Core 2.10.0-4.4.18 and 5.2.0-5.2.9 - Authenticated SQL Injection via Contact Activity API Sort Parameter
CVSS 7.6
CVE-2026-23980 MEDIUM
Apache Superset <6.0.0 - SQL Injection
CVSS 6.5
CVE-2026-23969 MEDIUM
Apache Superset <4.1.2 - SQL Injection
CVSS 6.5
CVE-2026-3069 HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3068 HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-27461 MEDIUM
Pimcore <=11.5.14.1/12.3.2 - SQL Injection
CVSS 4.9
CVE-2026-3057 MEDIUM
pearProjectApi <2.8.10 - SQL Injection
CVSS 6.3
CVE-2026-26198 CRITICAL
Ormar 0.9.9-0.22.0 - SQL Injection via Unsanitized Column Names in Aggregate Queries
CVSS 9.8
CVE-2026-3046 HIGH
itsourcecode E-Logbook 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3042 HIGH
itsourcecode Event Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-1367 HIGH
ManageEngine ADSelfService Plus <6522 - SQL Injection
CVSS 8.3
CVE-2026-24494 CRITICAL
Order Up Online Ordering System 1.0 - SQL Injection
CVSS 9.8
CVE-2026-2963 MEDIUM
Jinher OA C6 <20260210 - SQL Injection
CVSS 6.3
CVE-2026-2912 HIGH
Online Reviewer System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2867 HIGH
itsourcecode Vehicle Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2865 HIGH
Agri-Trading Online Shopping System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-27470 HIGH
ZoneMinder <=1.36.37, 1.37.61-1.38.0 - SQL Injection
CVSS 8.8
CVE-2026-2848 HIGH
SourceCodester Tourism Website 1.0 - SQL Injection
CVSS 7.3
CVE-2026-26745 MEDIUM
OpenSourcePOS 3.4.1 - SQL Injection
CVSS 5.3
CVE-2026-24959 HIGH
JS Help Desk <=3.0.1 - SQL Injection
CVSS 8.5
CVE-2026-24956 CRITICAL
Download Manager Addons for Elementor <=1.3.0 - SQL Injection
CVSS 9.3
Details
Vulnerabilities 19,501
Exploit Likelihood High