VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 197 of 1,043
  • CVE-2026-74254CriAug 17, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.

  • CVE-2026-74251CriAug 16, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without…

  • CVE-2026-67365CriAug 14, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

  • CVE-2026-66478CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.

  • CVE-2026-66472CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.

  • CVE-2026-66458CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.

  • CVE-2026-66446CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.

  • CVE-2026-66436CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.

  • CVE-2026-61969CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.

  • CVE-2026-61966CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.

  • CVE-2026-28142CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.

  • CVE-2026-28001CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

  • CVE-2026-66659CriAug 12, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.

  • CVE-2025-13294CriAug 10, 2026
    risk 0.60cvss —epss 0.01

    An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated…

  • CVE-2026-66447CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

  • CVE-2026-65546CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

  • CVE-2026-65520CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

  • CVE-2026-65508CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

  • CVE-2025-67649CriJul 31, 2026
    risk 0.60cvss —epss 0.00

    A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed…

  • CVE-2026-65876CriJul 27, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.