CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

18,856 vulnerabilities with CWE-89
CVE-2026-37593 LOW
Online Employees Work From Home Attendance System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-37592 LOW
Storage Unit Rental Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-37591 LOW
Storage Unit Rental Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-37590 LOW
Storage Unit Rental Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-37589 LOW
Storage Unit Rental Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-40315 CRITICAL
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
CVSS 9.8
CVE-2026-4352 HIGH
JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter
CVSS 7.5
CVE-2026-27681 CRITICAL
SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
CVSS 9.9
CVE-2026-32272 HIGH
Craft Commerce: Blind SQL Injection via hasVariant/hasProduct
CVE-2026-32271 HIGH
Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget
CVE-2026-6202 MEDIUM
code-projects Easy Blog Site post.php sql injection
CVSS 6.3
CVE-2026-6193 HIGH
PHPGurukul Daily Expense Tracking System register.php sql injection
CVSS 7.3
CVE-2026-6191 MEDIUM
itsourcecode Construction Management System equipments.php sql injection
CVSS 6.3
CVE-2026-6190 MEDIUM
itsourcecode Construction Management System employees.php sql injection
CVSS 6.3
CVE-2026-6189 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-36952 LOW
Online Thesis Archiving System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-36950 LOW
Online Thesis Archiving System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-36948 HIGH
Online Thesis Archiving System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-6188 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-6187 HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-36938 LOW
Online Resort Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-36937 LOW
Online Resort Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-34186 HIGH
SQL Injection in Custom Fields leads to Database Compromise
CVSS 8.8
CVE-2026-30813 HIGH
SQL Injection in Module Search leads to Database Compromise
CVSS 8.8
CVE-2026-6183 HIGH
code-projects Simple Content Management System index.php sql injection
CVSS 7.3
Details
Vulnerabilities 18,856
Exploit Likelihood High