CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,510 vulnerabilities with CWE-89
CVE-2026-2089 HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2088 HIGH
PHPGurukul Beauty Parlour Management System 1.1 - SQL Injection
CVSS 7.3
CVE-2026-2087 HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2083 HIGH
code-projects Social Networking Site 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2073 HIGH
isourcecode School Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-25544 CRITICAL
Payloadcms Drizzle < 3.73.0 - SQL Injection
CVSS 9.8
CVE-2026-24418 MEDIUM
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
CVE-2026-24417 MEDIUM
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
CVE-2026-24416 MEDIUM
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
CVE-2026-2060 HIGH
Simple Blood Donor Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-24419 MEDIUM
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
CVE-2026-2059 HIGH
Medical Center Portal Management System 1.0 - SQL Injection via ID Parameter in emp_edit1.php
CVSS 7.3
CVE-2026-2058 HIGH
mathurvishal CloudClassroom-PHP-Project - SQL Injection via gnamex Parameter
CVSS 7.3
CVE-2026-2057 HIGH
Medical Center Portal Management System 1.0 - SQL Injection via User Parameter in login.php
CVSS 7.3
CVE-2026-2018 HIGH
itsourcecode School Management System <1.0 - SQL Injection
CVSS 7.3
CVE-2026-2014 HIGH
iSourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2013 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2012 HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2011 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-21643 CRITICAL KEV
Fortinet FortiClientEMS <7.4.4 - SQL Injection
CVSS 9.8
CVE-2026-1517 MEDIUM
iomad < 5.0 - SQL Injection in Company Admin Block
CVSS 4.7
CVE-2026-25514 HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via Autocomplete CodeModel::all() Method
CVSS 8.8
CVE-2026-25513 HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8
CVE-2026-22044 MEDIUM
GLPI 0.85-10.0.22 - Authenticated SQL Injection
CVSS 6.5
CVE-2026-1370 MEDIUM
SIBS woocommerce payment gateway plugin - SQL Injection
CVSS 4.9
Details
Vulnerabilities 19,510
Exploit Likelihood High