CWE-943

Improper Neutralization of Special Elements in Data Query Logic

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

66 vulnerabilities with CWE-943
CVE-2026-40352 HIGH
FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover
CVSS 8.8
CVE-2026-40351 CRITICAL
FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass
CVSS 9.8
CVE-2026-34973 MEDIUM
phpMyFAQ <4.1.1 Search.php - LIKE Wildcard Injection
CVSS 5.3
CVE-2026-33980 HIGH
Azure Data Explorer MCP Server <=0.1.1 - KQL Injection
CVSS 8.3
CVE-2026-22558 HIGH
UniFi Network Application 9.0.118-10.1.89, 10.2.97 - Authenticated NoSQL Injection
CVSS 7.7
CVE-2026-3023 HIGH
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web
CVSS 8.8
CVE-2026-3022 MEDIUM
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web
CVSS 6.5
CVE-2026-3021 MEDIUM
Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web
CVSS 6.5
CVE-2026-32248 CRITICAL
Parse Server <9.6.0-alpha.12/8.6.38 - Auth Bypass
CVSS 9.8
CVE-2026-32247 HIGH
graphiti-core < 0.28.2 - Cypher Injection via SearchFilters.node_labels
CVSS 8.1
CVE-2026-31825 MEDIUM
Sylius SQL Injection via Order Direction Parameter
CVSS 5.3
CVE-2026-29793 CRITICAL
Feathersjs 5.0.0-5.0.41 - Command Injection
CVSS 9.8
CVE-2026-30941 HIGH
Parse Server <8.6.14/9.5.2-alpha.1 - NoSQL Injection
CVSS 7.5
CVE-2026-30833 MEDIUM
Rocket.Chat <8.2.0 - NoSQL Injection
CVSS 5.3
CVE-2026-28211 HIGH
NVDA Dev & Test Toolbox 2.0-8.0 - Code Injection
CVSS 7.8
CVE-2026-25591 MEDIUM
New API <0.10.8-alpha.10 - SQL Injection
CVSS 6.5
CVE-2026-25514 HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via Autocomplete CodeModel::all() Method
CVSS 8.8
CVE-2026-25513 HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8
CVE-2026-0504 LOW
SAP Identity Management - Info Disclosure
CVSS 3.8
CVE-2025-60357 HIGH
AhnLab EPP Management 1.0.14.32-6249 - NoSQL Injection via eventlog/agentEvent/list Endpoint
CVSS 8.1
CVE-2025-36442 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Denial of Service via Crafted Query with XML Columns
CVSS 6.5
CVE-2025-36366 MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via JSON_Object Scalar Function
CVSS 6.5
CVE-2025-36353 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Denial of Service via Data Query Logic
CVSS 6.2
CVE-2025-42884 MEDIUM
SAP NetWeaver Enterprise Portal - Info Disclosure
CVSS 6.5
CVE-2025-36185 MEDIUM
IBM Db2 12.1.0-12.1.2 - Denial of Service via Data Query Logic
CVSS 6.2
Details
Vulnerabilities 66