CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,510 vulnerabilities with CWE-89
CVE-2026-21875 CRITICAL
ClipBucket 5.3-5.5.2-187 - Blind SQL Injection via obj_id Parameter in Comment POST Request
CVSS 9.8
CVE-2026-21856 HIGH
Tarkov Data Manager < 2026-01-02 - Blind SQL Injection via Webhook/Scanner API
CVSS 7.2
CVE-2026-0607 HIGH
Online Music Site 1.0 - SQL Injection via AdminViewSongs.php ID Parameter
CVSS 7.3
CVE-2026-0606 HIGH
Online Music Site 1.0 - SQL Injection via Albums.php ID Parameter
CVSS 7.3
CVE-2026-0605 HIGH
Online Music Site 1.0 - SQL Injection via Login Username/Password Parameters
CVSS 7.3
CVE-2026-0597 MEDIUM
Campcodes Supplier Management System 1.0 - SQL Injection via txtRetailerAddress Parameter
CVSS 6.3
CVE-2026-0592 HIGH
Online Product Reservation System 1.0 - SQL Injection via User Registration Handler
CVSS 7.3
CVE-2026-0591 MEDIUM
Online Product Reservation System 1.0 - SQL Injection via Cart Update Handler
CVSS 6.3
CVE-2026-0590 MEDIUM
Online Product Reservation System 1.0 - SQL Injection via /app/checkout/delete.php ID Parameter
CVSS 6.3
CVE-2026-0585 HIGH
Online Product Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2026-0584 MEDIUM
Online Product Reservation System 1.0 - SQL Injection via ID Parameter in left_cart.php
CVSS 6.3
CVE-2026-0583 HIGH
Online Product Reservation System 1.0 - SQL Injection via User Login Email Parameter
CVSS 7.3
CVE-2026-0582 MEDIUM
itsourcecode Society Management System 1.0 - SQL Injection via Title Parameter in edit_activity_query.php
CVSS 6.3
CVE-2026-0579 HIGH
Online Product Reservation System 1.0 - SQL Injection via POST Parameter Handler
CVSS 7.3
CVE-2026-0578 HIGH
Online Product Reservation System 1.0 - SQL Injection via /handgunner-administrator/delete.php ID Parameter
CVSS 7.3
CVE-2026-0576 HIGH
Online Product Reservation System 1.0 - SQL Injection via Parameter Handler
CVSS 7.3
CVE-2026-0575 HIGH
Online Product Reservation System 1.0 - SQL Injection via Administrator Login Email/Password Parameters
CVSS 7.3
CVE-2026-0570 HIGH
Online Music Site 1.0 - SQL Injection via Feedback.php fname Parameter
CVSS 7.3
CVE-2026-0569 HIGH
Online Music Site 1.0 - SQL Injection via AlbumByCategory.php ID Parameter
CVSS 7.3
CVE-2026-0568 HIGH
Online Music Site 1.0 - SQL Injection via ViewSongs.php ID Parameter
CVSS 7.3
CVE-2026-0567 HIGH
code-projects Content Management System 1.0 - SQL Injection via ID Parameter in pages.php
CVSS 7.3
CVE-2026-0565 HIGH
code-projects Content Management System 1.0 - SQL Injection via del Parameter in admin/delete.php
CVSS 7.3
CVE-2026-0546 HIGH
code-projects Content Management System 1.0 - SQL Injection via search.php Value Parameter
CVSS 7.3
CVE-2026-0544 HIGH
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter in /student/index.php
CVSS 7.3
CVE-2025-61029 HIGH
openlink virtuoso-opensource 7.2.11 - Denial of Service via Crafted SQL Statements
CVSS 7.5
Details
Vulnerabilities 19,510
Exploit Likelihood High