CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 197 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-74254 | Cri | 0.60 | — | 0.00 | Aug 17, 2026 | Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend. | ||
| CVE-2026-74251 | Cri | 0.60 | — | 0.00 | Aug 16, 2026 | Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without… | ||
| CVE-2026-67365 | Cri | 0.60 | — | 0.00 | Aug 14, 2026 | Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account. | ||
| CVE-2026-66478 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | ||
| CVE-2026-66472 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | ||
| CVE-2026-66458 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | ||
| CVE-2026-66446 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||
| CVE-2026-66436 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | ||
| CVE-2026-61969 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. | ||
| CVE-2026-61966 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. | ||
| CVE-2026-28142 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | ||
| CVE-2026-28001 | Cri | 0.60 | 9.3 | 0.00 | Aug 13, 2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||
| CVE-2026-66659 | Cri | 0.60 | 9.3 | 0.00 | Aug 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9. | ||
| CVE-2025-13294 | Cri | 0.60 | — | 0.01 | Aug 10, 2026 | An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated… | ||
| CVE-2026-66447 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | ||
| CVE-2026-65546 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions. | ||
| CVE-2026-65520 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | ||
| CVE-2026-65508 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | ||
| CVE-2025-67649 | Cri | 0.60 | — | 0.00 | Jul 31, 2026 | A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed… | ||
| CVE-2026-65876 | Cri | 0.60 | — | 0.00 | Jul 27, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector. |
- risk 0.60cvss —epss 0.00
Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.
- risk 0.60cvss —epss 0.00
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public shop items page are concatenated raw into SQL WHERE clauses without…
- risk 0.60cvss —epss 0.00
Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
- risk 0.60cvss 9.3epss 0.00
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
- risk 0.60cvss 9.3epss 0.00
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
- risk 0.60cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.
- risk 0.60cvss —epss 0.01
An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated…
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
- risk 0.60cvss —epss 0.00
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed…
- risk 0.60cvss —epss 0.00
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.