VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 195 of 1,043
  • CVE-2026-88854CriSep 20, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real…

  • CVE-2026-81800CriSep 10, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

  • CVE-2026-78082CriSep 10, 2026
    risk 0.60cvss —epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and…

  • CVE-2026-84768CriSep 3, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

  • CVE-2026-78080CriSep 3, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.

  • CVE-2026-81286CriSep 2, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.

  • CVE-2026-81763CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

  • CVE-2026-81756CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

  • CVE-2026-81293CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

  • CVE-2026-81675CriAug 27, 2026
    risk 0.60cvss —epss 0.00

    The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt…

  • CVE-2026-81674CriAug 27, 2026
    risk 0.60cvss —epss 0.00

    The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results…

  • CVE-2026-81673CriAug 27, 2026
    risk 0.60cvss —epss 0.01

    The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including them in SQL queries. This allows a remote attacker to inject SQL syntax and…

  • CVE-2026-81672CriAug 27, 2026
    risk 0.60cvss —epss 0.00

    SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The…

  • CVE-2026-78288CriAug 27, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.

  • CVE-2026-78260CriAug 27, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

  • CVE-2026-32479CriAug 27, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

  • CVE-2026-32555CriAug 24, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Boost <= 2.0.4 versions.

  • CVE-2026-32554CriAug 24, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.

  • CVE-2026-32551CriAug 24, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essential allows SQL Injection. This issue affects Woo Essential: from n/a through 4.3.0.

  • CVE-2026-77994CriAug 24, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.