VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 224 of 1,043
  • CVE-2026-78315HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

  • CVE-2026-78314HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

  • CVE-2026-76904CriAug 21, 2026
    risk 0.57cvss 9.8epss 0.04

    GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains`…

  • CVE-2026-61518HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods is concatenated directly into SQL WHERE clauses without integer casting or parameterized query binding. The built-in SQL injection…

  • CVE-2026-71176HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information…

  • CVE-2026-67917CriAug 17, 2026
    risk 0.57cvss 9.8epss 0.01

    zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanitization. This allows a remote…

  • CVE-2026-59109HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement…

  • CVE-2026-11840HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.03

    Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

  • CVE-2026-73332HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which…

  • CVE-2026-13613HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.

  • CVE-2026-73211CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables,…

  • CVE-2026-46670CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.02

    YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read…

  • CVE-2026-72775HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping. An authenticated user can inject…

  • CVE-2026-72750HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data…

  • CVE-2026-72562HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without…

  • CVE-2026-72558HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access…

  • CVE-2026-71288HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-named parameter, and concatenates both directly into an SQL ORDER BY clause with no allowlist or validation. Since ORDER BY columns cannot be bound via…

  • CVE-2026-71287HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as…

  • CVE-2026-69240CriAug 3, 2026
    risk 0.57cvss 9.8epss 0.01

    Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a…

  • CVE-2026-65321CriAug 2, 2026
    risk 0.57cvss 9.8epss 0.01

    PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that…