VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 292 of 1,043
  • CVE-2026-84047HigSep 12, 2026
    risk 0.56cvss 8.6epss 0.00

    The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

  • CVE-2026-80491HigSep 12, 2026
    risk 0.56cvss 8.6epss 0.00

    The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

  • CVE-2026-79322HigSep 9, 2026
    risk 0.56cvss 8.6epss 0.00

    SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.

  • CVE-2026-84068HigSep 9, 2026
    risk 0.56cvss 8.6epss 0.00

    The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection.

  • CVE-2026-14962HigSep 9, 2026
    risk 0.56cvss 8.6epss 0.00

    The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database.

  • CVE-2026-82304HigSep 5, 2026
    risk 0.56cvss 8.6epss 0.00

    The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

  • CVE-2026-76176HigSep 3, 2026
    risk 0.56cvss —epss 0.00

    SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter…

  • CVE-2026-76175HigSep 3, 2026
    risk 0.56cvss —epss 0.00

    SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to…

  • CVE-2026-19754HigSep 2, 2026
    risk 0.56cvss —epss 0.00

    Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a…

  • CVE-2026-16061HigAug 29, 2026
    risk 0.56cvss 8.6epss 0.00

    The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

  • CVE-2026-78614HigAug 28, 2026
    risk 0.56cvss —epss 0.01

    WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted…

  • CVE-2026-78613HigAug 28, 2026
    risk 0.56cvss —epss 0.01

    WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted…

  • CVE-2026-78612HigAug 28, 2026
    risk 0.56cvss —epss 0.01

    WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted…

  • CVE-2026-76613HigAug 21, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.

  • CVE-2026-16950HigAug 19, 2026
    risk 0.56cvss 8.6epss 0.00

    The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

  • CVE-2026-12983HigAug 19, 2026
    risk 0.56cvss 8.6epss 0.00

    The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. The same handler also performs a database table truncation without any authorization check, allowing…

  • CVE-2026-71571HigAug 14, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

  • CVE-2026-73850HigAug 14, 2026
    risk 0.56cvss —epss 0.00

    Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php.

  • CVE-2026-15205HigAug 14, 2026
    risk 0.56cvss 8.6epss 0.00

    The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature.…

  • CVE-2026-18474HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.