CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 195 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-88854 | Cri | 0.60 | — | 0.00 | Sep 20, 2026 | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real… | ||
| CVE-2026-81800 | Cri | 0.60 | 9.3 | 0.00 | Sep 10, 2026 | Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | ||
| CVE-2026-78082 | Cri | 0.60 | — | 0.01 | Sep 10, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and… | ||
| CVE-2026-84768 | Cri | 0.60 | 9.3 | 0.00 | Sep 3, 2026 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | ||
| CVE-2026-78080 | Cri | 0.60 | — | 0.00 | Sep 3, 2026 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors. | ||
| CVE-2026-81286 | Cri | 0.60 | 9.3 | 0.00 | Sep 2, 2026 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions. | ||
| CVE-2026-81763 | Cri | 0.60 | 9.3 | 0.00 | Aug 31, 2026 | Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions. | ||
| CVE-2026-81756 | Cri | 0.60 | 9.3 | 0.00 | Aug 31, 2026 | Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions. | ||
| CVE-2026-81293 | Cri | 0.60 | 9.3 | 0.00 | Aug 31, 2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | ||
| CVE-2026-81675 | — | Cri | 0.60 | — | 0.00 | Aug 27, 2026 | The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt… | |
| CVE-2026-81674 | — | Cri | 0.60 | — | 0.00 | Aug 27, 2026 | The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results… | |
| CVE-2026-81673 | — | Cri | 0.60 | — | 0.01 | Aug 27, 2026 | The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including them in SQL queries. This allows a remote attacker to inject SQL syntax and… | |
| CVE-2026-81672 | — | Cri | 0.60 | — | 0.00 | Aug 27, 2026 | SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The… | |
| CVE-2026-78288 | Cri | 0.60 | 9.3 | 0.00 | Aug 27, 2026 | Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions. | ||
| CVE-2026-78260 | Cri | 0.60 | 9.3 | 0.00 | Aug 27, 2026 | Unauthenticated SQL Injection in Epayco <= 8.4.6 versions. | ||
| CVE-2026-32479 | Cri | 0.60 | 9.3 | 0.00 | Aug 27, 2026 | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. | ||
| CVE-2026-32555 | Cri | 0.60 | 9.3 | 0.00 | Aug 24, 2026 | Unauthenticated SQL Injection in Boost <= 2.0.4 versions. | ||
| CVE-2026-32554 | Cri | 0.60 | 9.3 | 0.00 | Aug 24, 2026 | Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | ||
| CVE-2026-32551 | Cri | 0.60 | 9.3 | 0.00 | Aug 24, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essential allows SQL Injection. This issue affects Woo Essential: from n/a through 4.3.0. | ||
| CVE-2026-77994 | Cri | 0.60 | — | 0.00 | Aug 24, 2026 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model. |
- risk 0.60cvss —epss 0.00
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real…
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
- risk 0.60cvss —epss 0.01
Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and…
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.
- risk 0.60cvss —epss 0.00
Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
- risk 0.60cvss —epss 0.00
The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt…
- risk 0.60cvss —epss 0.00
The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results…
- risk 0.60cvss —epss 0.01
The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including them in SQL queries. This allows a remote attacker to inject SQL syntax and…
- risk 0.60cvss —epss 0.00
SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The…
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
- risk 0.60cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essential allows SQL Injection. This issue affects Woo Essential: from n/a through 4.3.0.
- risk 0.60cvss —epss 0.00
Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.