CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
18,856 vulnerabilities with CWE-89
CVE-2026-37593
LOW
Online Employees Work From Home Attendance System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-37592
LOW
Storage Unit Rental Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-37591
LOW
Storage Unit Rental Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-37590
LOW
Storage Unit Rental Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-37589
LOW
Storage Unit Rental Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-40315
CRITICAL
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
CVSS 9.8
CVE-2026-4352
HIGH
JetEngine <= 3.8.6.1 - Unauthenticated SQL Injection via '_cct_search' Parameter
CVSS 7.5
CVE-2026-27681
CRITICAL
SQL Injection vulnerability in SAP Business Planning and Consolidation and SAP Business Warehouse
CVSS 9.9
CVE-2026-32272
HIGH
Craft Commerce: Blind SQL Injection via hasVariant/hasProduct
CVE-2026-32271
HIGH
Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget
CVE-2026-6202
MEDIUM
code-projects Easy Blog Site post.php sql injection
CVSS 6.3
CVE-2026-6193
HIGH
PHPGurukul Daily Expense Tracking System register.php sql injection
CVSS 7.3
CVE-2026-6191
MEDIUM
itsourcecode Construction Management System equipments.php sql injection
CVSS 6.3
CVE-2026-6190
MEDIUM
itsourcecode Construction Management System employees.php sql injection
CVSS 6.3
CVE-2026-6189
HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-36952
LOW
Online Thesis Archiving System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-36950
LOW
Online Thesis Archiving System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-36948
HIGH
Online Thesis Archiving System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-6188
HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-6187
HIGH
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
CVSS 7.3
CVE-2026-36938
LOW
Online Resort Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-36937
LOW
Online Resort Management System 1.0 - SQL Injection
CVSS 2.7
CVE-2026-34186
HIGH
SQL Injection in Custom Fields leads to Database Compromise
CVSS 8.8
CVE-2026-30813
HIGH
SQL Injection in Module Search leads to Database Compromise
CVSS 8.8
CVE-2026-6183
HIGH
code-projects Simple Content Management System index.php sql injection
CVSS 7.3
Details
Vulnerabilities
18,856
Exploit Likelihood
High