CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,510 vulnerabilities with CWE-89
CVE-2026-23723 HIGH
WeGIA < 3.6.2 - Authenticated SQL Injection via Atendido_ocorrenciaControle id_memorando Parameter
CVSS 7.2
CVE-2026-23492 HIGH
Pimcore <12.3.1-11.5.14 - SQL Injection
CVSS 8.8
CVE-2026-0678 MEDIUM
Flat Shipping Rate by City for WooCommerce <1.0.3 - SQL Injection
CVSS 4.9
CVE-2026-20947 HIGH
Microsoft Office SharePoint - SQL Injection
CVSS 8.8
CVE-2026-0501 CRITICAL
SAP S/4HANA Private Cloud & On-Premise - SQL Injection
CVSS 9.9
CVE-2026-0852 HIGH
Online Music Site 1.0 - SQL Injection via AdminUpdateUser.php ID Parameter
CVSS 7.3
CVE-2026-0851 HIGH
Online Music Site 1.0 - SQL Injection via txtusername Parameter
CVSS 7.3
CVE-2026-0850 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via delete_activity.php activity_id Parameter
CVSS 4.7
CVE-2026-0843 MEDIUM
jjjfood/jjjshop_food <20260103 - SQL Injection
CVSS 6.3
CVE-2026-22687 MEDIUM
WeKnora < 0.2.5 - SQL Injection via Prompt-Based Bypass
CVSS 5.6
CVE-2026-22596 MEDIUM
Ghost 5.90.0-5.130.5 and 6.0.0-6.10.3 - Authenticated SQL Injection via Admin API Members Events Endpoint
CVSS 6.7
CVE-2026-22197 HIGH
GestSup < 3.2.56 - Authenticated SQL Injection in Asset List Functionality
CVSS 8.1
CVE-2026-22196 HIGH
GestSup < 3.2.56 - Authenticated SQL Injection in Ticket Creation
CVSS 8.1
CVE-2026-22195 HIGH
GestSup < 3.2.56 - Authenticated SQL Injection via Search Bar
CVSS 8.1
CVE-2026-0803 MEDIUM
Online Course Registration System < 3.1 - SQL Injection via enroll.php Parameters
CVSS 6.3
CVE-2026-0733 MEDIUM
Online Course Registration System < 3.1 - SQL Injection via id/cid Parameter in manage-students.php
CVSS 6.3
CVE-2026-0729 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via Title Parameter in add_activity.php
CVSS 4.7
CVE-2026-0728 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter in delete_admin.php
CVSS 4.7
CVE-2026-21892 MEDIUM
Parsl < 2026.01.05 - Unauthenticated SQL Injection via Workflow ID Parameter
CVSS 5.3
CVE-2026-22242 MEDIUM
CoreShop < 4.1.8 - Authenticated Blind SQL Injection
CVSS 4.9
CVE-2026-0701 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in add_admin.php
CVSS 4.7
CVE-2026-0700 HIGH
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in check_admin.php
CVSS 7.3
CVE-2026-0699 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via activity_id Parameter
CVSS 4.7
CVE-2026-0698 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter
CVSS 4.7
CVE-2026-0697 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter
CVSS 4.7
Details
Vulnerabilities 19,510
Exploit Likelihood High