CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,510 vulnerabilities with CWE-89
CVE-2026-2495 HIGH
WPNakama Plugin <0.6.5 - SQL Injection
CVSS 7.5
CVE-2026-1639 MEDIUM
Taskbuilder WordPress Plugin <5.0.2 - SQL Injection
CVSS 6.5
CVE-2026-2576 HIGH
Business Directory Plugin 6.4.2 - SQL Injection
CVSS 7.5
CVE-2026-2621 HIGH
Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0 - SQL Injection via PGUID Parameter
CVSS 7.3
CVE-2026-2620 HIGH
Huace Monitoring 2.2 - SQL Injection
CVSS 7.3
CVE-2026-2247 HIGH
Clickedu SaaS platform - Authenticated SQL Injection via Report Generation URL Parameter
CVE-2026-2553 MEDIUM
Hotel-Management-System - SQL Injection
CVSS 6.3
CVE-2026-1258 MEDIUM
Mail Mint <1.19.2 - Blind SQL Injection
CVSS 4.9
CVE-2026-2024 HIGH
PhotoStack Gallery <0.4.1 - SQL Injection
CVSS 7.5
CVE-2026-22821 MEDIUM
more_reporting < 1.9.4 - SQL Injection via Date Change
CVSS 4.9
CVE-2026-25993 CRITICAL
evershop < 2.1.0 - SQL Injection via Category URL Key Processing
CVSS 9.8
CVE-2026-25947 HIGH
Worklenz < 2.1.7 - SQL Injection in Project and Task Management Controllers
CVSS 8.8
CVE-2026-1602 MEDIUM
Ivanti Endpoint Manager < 2024 SU5 - Authenticated SQL Injection
CVSS 6.5
CVE-2026-2094 HIGH
Flowring Docpedia - Authenticated SQL Injection
CVSS 8.8
CVE-2026-2093 HIGH
Flowring Docpedia - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-25495 HIGH
Craft CMS 4.0.0-4.16.17 and 5.0.0-RC1-5.8.21 - Authenticated SQL Injection via Element Index OrderBy Parameter
CVSS 8.8
CVE-2026-2225 HIGH
itsourcecode News Portal Project 1.0 - SQL Injection via Administrator Login Email Parameter
CVSS 7.3
CVE-2026-2236 HIGH
HGiga C&Cm@il package olln-base < 7.0-978 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2026-2235 MEDIUM
HGiga C&Cm@il package olln-base < 7.0-978 - Authenticated SQL Injection
CVSS 6.5
CVE-2026-2223 HIGH
Online Reviewer System 1.0 - SQL Injection via ID Parameter
CVSS 7.3
CVE-2026-2221 HIGH
Online Reviewer System 1.0 - SQL Injection via Username Parameter in Login
CVSS 7.3
CVE-2026-2220 HIGH
Online Reviewer System 1.0 - SQL Injection via difficulty_id Parameter
CVSS 7.3
CVE-2026-2217 HIGH
Event Management System 1.0 - SQL Injection via ID Parameter in manage_user.php
CVSS 7.3
CVE-2026-2212 HIGH
Online Music Site 1.0 - SQL Injection via AdminEditCategory.php ID Parameter
CVSS 7.3
CVE-2026-2211 HIGH
Online Music Site 1.0 - SQL Injection via AdminDeleteCategory.php ID Parameter
CVSS 7.3
Details
Vulnerabilities 19,510
Exploit Likelihood High