CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,510 vulnerabilities with CWE-89
CVE-2026-23723
HIGH
WeGIA < 3.6.2 - Authenticated SQL Injection via Atendido_ocorrenciaControle id_memorando Parameter
CVSS 7.2
CVE-2026-23492
HIGH
Pimcore <12.3.1-11.5.14 - SQL Injection
CVSS 8.8
CVE-2026-0678
MEDIUM
Flat Shipping Rate by City for WooCommerce <1.0.3 - SQL Injection
CVSS 4.9
CVE-2026-20947
HIGH
Microsoft Office SharePoint - SQL Injection
CVSS 8.8
CVE-2026-0501
CRITICAL
SAP S/4HANA Private Cloud & On-Premise - SQL Injection
CVSS 9.9
CVE-2026-0852
HIGH
Online Music Site 1.0 - SQL Injection via AdminUpdateUser.php ID Parameter
CVSS 7.3
CVE-2026-0851
HIGH
Online Music Site 1.0 - SQL Injection via txtusername Parameter
CVSS 7.3
CVE-2026-0850
MEDIUM
Intern Membership Management System 1.0 - SQL Injection via delete_activity.php activity_id Parameter
CVSS 4.7
CVE-2026-0843
MEDIUM
jjjfood/jjjshop_food <20260103 - SQL Injection
CVSS 6.3
CVE-2026-22687
MEDIUM
WeKnora < 0.2.5 - SQL Injection via Prompt-Based Bypass
CVSS 5.6
CVE-2026-22596
MEDIUM
Ghost 5.90.0-5.130.5 and 6.0.0-6.10.3 - Authenticated SQL Injection via Admin API Members Events Endpoint
CVSS 6.7
CVE-2026-22197
HIGH
GestSup < 3.2.56 - Authenticated SQL Injection in Asset List Functionality
CVSS 8.1
CVE-2026-22196
HIGH
GestSup < 3.2.56 - Authenticated SQL Injection in Ticket Creation
CVSS 8.1
CVE-2026-22195
HIGH
GestSup < 3.2.56 - Authenticated SQL Injection via Search Bar
CVSS 8.1
CVE-2026-0803
MEDIUM
Online Course Registration System < 3.1 - SQL Injection via enroll.php Parameters
CVSS 6.3
CVE-2026-0733
MEDIUM
Online Course Registration System < 3.1 - SQL Injection via id/cid Parameter in manage-students.php
CVSS 6.3
CVE-2026-0729
MEDIUM
Intern Membership Management System 1.0 - SQL Injection via Title Parameter in add_activity.php
CVSS 4.7
CVE-2026-0728
MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter in delete_admin.php
CVSS 4.7
CVE-2026-21892
MEDIUM
Parsl < 2026.01.05 - Unauthenticated SQL Injection via Workflow ID Parameter
CVSS 5.3
CVE-2026-22242
MEDIUM
CoreShop < 4.1.8 - Authenticated Blind SQL Injection
CVSS 4.9
CVE-2026-0701
MEDIUM
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in add_admin.php
CVSS 4.7
CVE-2026-0700
HIGH
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in check_admin.php
CVSS 7.3
CVE-2026-0699
MEDIUM
Intern Membership Management System 1.0 - SQL Injection via activity_id Parameter
CVSS 4.7
CVE-2026-0698
MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter
CVSS 4.7
CVE-2026-0697
MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter
CVSS 4.7
Details
Vulnerabilities
19,510
Exploit Likelihood
High