CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,510 vulnerabilities with CWE-89
CVE-2026-2089
HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2088
HIGH
PHPGurukul Beauty Parlour Management System 1.1 - SQL Injection
CVSS 7.3
CVE-2026-2087
HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2083
HIGH
code-projects Social Networking Site 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2073
HIGH
isourcecode School Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-25544
CRITICAL
Payloadcms Drizzle < 3.73.0 - SQL Injection
CVSS 9.8
CVE-2026-24418
MEDIUM
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
CVE-2026-24417
MEDIUM
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
CVE-2026-24416
MEDIUM
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
CVE-2026-2060
HIGH
Simple Blood Donor Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-24419
MEDIUM
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
CVE-2026-2059
HIGH
Medical Center Portal Management System 1.0 - SQL Injection via ID Parameter in emp_edit1.php
CVSS 7.3
CVE-2026-2058
HIGH
mathurvishal CloudClassroom-PHP-Project - SQL Injection via gnamex Parameter
CVSS 7.3
CVE-2026-2057
HIGH
Medical Center Portal Management System 1.0 - SQL Injection via User Parameter in login.php
CVSS 7.3
CVE-2026-2018
HIGH
itsourcecode School Management System <1.0 - SQL Injection
CVSS 7.3
CVE-2026-2014
HIGH
iSourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2013
HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2012
HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2011
HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-21643
CRITICAL
KEV
Fortinet FortiClientEMS <7.4.4 - SQL Injection
CVSS 9.8
CVE-2026-1517
MEDIUM
iomad < 5.0 - SQL Injection in Company Admin Block
CVSS 4.7
CVE-2026-25514
HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via Autocomplete CodeModel::all() Method
CVSS 8.8
CVE-2026-25513
HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8
CVE-2026-22044
MEDIUM
GLPI 0.85-10.0.22 - Authenticated SQL Injection
CVSS 6.5
CVE-2026-1370
MEDIUM
SIBS woocommerce payment gateway plugin - SQL Injection
CVSS 4.9
Details
Vulnerabilities
19,510
Exploit Likelihood
High