CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,510 vulnerabilities with CWE-89
CVE-2026-2199
HIGH
Online Reviewer System 1.0 - SQL Injection via ID Parameter in user-delete.php
CVSS 7.3
CVE-2026-2198
HIGH
Online Reviewer System 1.0 - SQL Injection via difficulty_id Parameter
CVSS 7.3
CVE-2026-2197
HIGH
Online Reviewer System 1.0 - SQL Injection via exam-delete.php test_id Parameter
CVSS 7.3
CVE-2026-2196
HIGH
Online Reviewer System 1.0 - SQL Injection via exam-update.php test_id Parameter
CVSS 7.3
CVE-2026-2195
HIGH
Online Reviewer System 1.0 - SQL Injection via ID Parameter
CVSS 7.3
CVE-2026-2190
HIGH
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter in controller.php
CVSS 7.3
CVE-2026-2189
HIGH
itsourcecode School Management System 1.0 - SQL Injection via ay Parameter
CVSS 7.3
CVE-2026-2179
MEDIUM
PHPGurukul Hospital Management System 4.0 - SQL Injection via /admin/manage-users.php ID Parameter
CVSS 4.7
CVE-2026-2176
MEDIUM
Contact Management System 1.0 - SQL Injection via selecteditem[0] Argument
CVSS 6.3
CVE-2026-2173
HIGH
Online Examination System 1.0 - SQL Injection via login.php Username/Password Parameters
CVSS 7.3
CVE-2026-2172
HIGH
Online Application System for Admission 1.0 - SQL Injection via Login Endpoint
CVSS 7.3
CVE-2026-2171
HIGH
Online Student Management System 1.0 - SQL Injection via Login Component
CVSS 7.3
CVE-2026-2166
HIGH
Online Reviewer System 1.0 - SQL Injection via Login Username/Password Parameter
CVSS 7.3
CVE-2026-2162
MEDIUM
News Portal Project 1.0 - SQL Injection via pagetitle Parameter in /admin/aboutus.php
CVSS 4.7
CVE-2026-2161
HIGH
itsourcecode Directory Management System 1.0 - SQL Injection via /admin/forget-password.php Email Parameter
CVSS 7.3
CVE-2026-2158
HIGH
Student Web Portal 1.0 - SQL Injection via Username Parameter in check_user.php
CVSS 7.3
CVE-2026-2136
HIGH
projectworlds Online Food Ordering System 1.0 - SQL Injection via /view-ticket.php ID Parameter
CVSS 7.3
CVE-2026-2134
MEDIUM
PHPGurukul Hospital Management System 4.0 - SQL Injection via ID Parameter in manage-doctors.php
CVSS 4.7
CVE-2026-2132
HIGH
Online Music Site 1.0 - SQL Injection via AdminUpdateCategory txtcat Parameter
CVSS 7.3
CVE-2026-2122
MEDIUM
Xiaopi Panel <20260126 - SQL Injection
CVSS 6.3
CVE-2026-2117
HIGH
Society Management System 1.0 - SQL Injection via activity_id Parameter in edit_activity.php
CVSS 7.3
CVE-2026-2116
HIGH
Society Management System 1.0 - SQL Injection via expenses_id Parameter in edit_expenses.php
CVSS 7.3
CVE-2026-2115
HIGH
Society Management System 1.0 - SQL Injection via Expenses ID Parameter
CVSS 7.3
CVE-2026-2114
HIGH
Society Management System 1.0 - SQL Injection via admin_id Parameter in edit_admin.php
CVSS 7.3
CVE-2026-2090
HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities
19,510
Exploit Likelihood
High