CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,396 vulnerabilities with CWE-89
CVE-2026-45545 HIGH
Nextcloud Tables 0.7.0-0.7.6, 0.8.0-0.8.9, 0.9.0-0.9.7, 1.0.0-1.0.3 - Authenticated SQL Injection via Stored Input
CVSS 8.2
CVE-2026-42672 CRITICAL
WordPress WP Directory Kit plugin <= 1.5.1 - SQL Injection vulnerability
CVSS 9.3
CVE-2026-10265 MEDIUM
itsourcecode Content Management System edit_topic.php sql injection
CVSS 6.3
CVE-2026-10263 HIGH
SourceCodester Computer Repair Shop Management System manage_product.php sql injection
CVSS 7.3
CVE-2026-10262 HIGH
code-projects Real State Services Login loginuser.php sql injection
CVSS 7.3
CVE-2026-10261 HIGH
CodeAstro Online Job Portal application_status.php sql injection
CVSS 7.3
CVE-2026-10260 HIGH
CodeAstro Online Job Portal delete-jobs.php sql injection
CVSS 7.3
CVE-2026-10258 MEDIUM
itsourcecode Content Management System add_sub_topic.php sql injection
CVSS 6.3
CVE-2026-10257 MEDIUM
itsourcecode Content Management System update_ss_img.php sql injection
CVSS 6.3
CVE-2026-10256 MEDIUM
itsourcecode Content Management System save_comment.php sql injection
CVSS 6.3
CVE-2026-10253 HIGH
itsourcecode Online House Rental System manage_payment.php sql injection
CVSS 7.3
CVE-2026-10252 HIGH
itsourcecode Online House Rental System manage_tenant.php sql injection
CVSS 7.3
CVE-2026-10251 HIGH
itsourcecode Online House Rental System ajax.php login sql injection
CVSS 7.3
CVE-2026-10250 HIGH
itsourcecode Online Blood Bank Management System campsdetails.php sql injection
CVSS 7.3
CVE-2026-10249 HIGH
itsourcecode Online Blood Bank Management System viewrequest.php sql injection
CVSS 7.3
CVE-2026-40546 HIGH
Multiple SQL Injections in SOPlanning
CVE-2026-10242 MEDIUM
itsourcecode Content Management System instructions.php sql injection
CVSS 6.3
CVE-2026-10237 MEDIUM
SourceCodester Water Billing Management System User Management manage_user sql injection
CVSS 4.7
CVE-2026-10235 MEDIUM
CodeAstro Ingredients Stock Management System stock_manager.php sql injection
CVSS 6.3
CVE-2026-10227 HIGH
raisulislamg4 student_management_system_by_php User Creation add_user_check.php sql injection
CVSS 7.3
CVE-2026-10226 HIGH
raisulislamg4 student_management_system_by_php delete.php sql injection
CVSS 7.3
CVE-2026-10225 HIGH
raisulislamg4 student_management_system_by_php Login login_check.php sql injection
CVSS 7.3
CVE-2026-10209 MEDIUM
code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection
CVSS 6.3
CVE-2026-10208 HIGH
code-projects Online Hospital Management System login_1.php login_user sql injection
CVSS 7.3
CVE-2026-10204 MEDIUM
OFCMS JSON Query SysUserController.java query sql injection
CVSS 6.3
Details
Vulnerabilities 19,396
Exploit Likelihood High