CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,510 vulnerabilities with CWE-89
CVE-2026-21875
CRITICAL
ClipBucket 5.3-5.5.2-187 - Blind SQL Injection via obj_id Parameter in Comment POST Request
CVSS 9.8
CVE-2026-21856
HIGH
Tarkov Data Manager < 2026-01-02 - Blind SQL Injection via Webhook/Scanner API
CVSS 7.2
CVE-2026-0607
HIGH
Online Music Site 1.0 - SQL Injection via AdminViewSongs.php ID Parameter
CVSS 7.3
CVE-2026-0606
HIGH
Online Music Site 1.0 - SQL Injection via Albums.php ID Parameter
CVSS 7.3
CVE-2026-0605
HIGH
Online Music Site 1.0 - SQL Injection via Login Username/Password Parameters
CVSS 7.3
CVE-2026-0597
MEDIUM
Campcodes Supplier Management System 1.0 - SQL Injection via txtRetailerAddress Parameter
CVSS 6.3
CVE-2026-0592
HIGH
Online Product Reservation System 1.0 - SQL Injection via User Registration Handler
CVSS 7.3
CVE-2026-0591
MEDIUM
Online Product Reservation System 1.0 - SQL Injection via Cart Update Handler
CVSS 6.3
CVE-2026-0590
MEDIUM
Online Product Reservation System 1.0 - SQL Injection via /app/checkout/delete.php ID Parameter
CVSS 6.3
CVE-2026-0585
HIGH
Online Product Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2026-0584
MEDIUM
Online Product Reservation System 1.0 - SQL Injection via ID Parameter in left_cart.php
CVSS 6.3
CVE-2026-0583
HIGH
Online Product Reservation System 1.0 - SQL Injection via User Login Email Parameter
CVSS 7.3
CVE-2026-0582
MEDIUM
itsourcecode Society Management System 1.0 - SQL Injection via Title Parameter in edit_activity_query.php
CVSS 6.3
CVE-2026-0579
HIGH
Online Product Reservation System 1.0 - SQL Injection via POST Parameter Handler
CVSS 7.3
CVE-2026-0578
HIGH
Online Product Reservation System 1.0 - SQL Injection via /handgunner-administrator/delete.php ID Parameter
CVSS 7.3
CVE-2026-0576
HIGH
Online Product Reservation System 1.0 - SQL Injection via Parameter Handler
CVSS 7.3
CVE-2026-0575
HIGH
Online Product Reservation System 1.0 - SQL Injection via Administrator Login Email/Password Parameters
CVSS 7.3
CVE-2026-0570
HIGH
Online Music Site 1.0 - SQL Injection via Feedback.php fname Parameter
CVSS 7.3
CVE-2026-0569
HIGH
Online Music Site 1.0 - SQL Injection via AlbumByCategory.php ID Parameter
CVSS 7.3
CVE-2026-0568
HIGH
Online Music Site 1.0 - SQL Injection via ViewSongs.php ID Parameter
CVSS 7.3
CVE-2026-0567
HIGH
code-projects Content Management System 1.0 - SQL Injection via ID Parameter in pages.php
CVSS 7.3
CVE-2026-0565
HIGH
code-projects Content Management System 1.0 - SQL Injection via del Parameter in admin/delete.php
CVSS 7.3
CVE-2026-0546
HIGH
code-projects Content Management System 1.0 - SQL Injection via search.php Value Parameter
CVSS 7.3
CVE-2026-0544
HIGH
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter in /student/index.php
CVSS 7.3
CVE-2025-61029
HIGH
openlink virtuoso-opensource 7.2.11 - Denial of Service via Crafted SQL Statements
CVSS 7.5
Details
Vulnerabilities
19,510
Exploit Likelihood
High