VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 223 of 1,043
  • CVE-2026-71808HigSep 9, 2026
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and…

  • CVE-2026-69716HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-67370HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-66820HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-66819HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62895HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-19633HigSep 6, 2026
    risk 0.57cvss 8.8epss 0.00

    PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking…

  • CVE-2026-52691HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.  This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired,…

  • CVE-2026-18198HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe.

  • CVE-2026-85540HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.01

    DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2026-14828HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.01

    Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.

  • CVE-2026-18630HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4…

  • CVE-2026-5956HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026.

  • CVE-2026-55634CriAug 28, 2026
    risk 0.57cvss 9.9epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an…

  • CVE-2026-78072HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1

  • CVE-2026-81677HigAug 27, 2026
    risk 0.57cvss —epss 0.00

    The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of…

  • CVE-2026-81676HigAug 27, 2026
    risk 0.57cvss —epss 0.00

    A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL…

  • CVE-2026-19949HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2026-78317HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

  • CVE-2026-78316HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.