VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 296 of 1,043
  • CVE-2021-26830CriApr 16, 2021
    risk 0.56cvss 9.1epss 0.05

    SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.

  • CVE-2020-5504HigJan 9, 2020
    risk 0.56cvss 8.8epss 0.39

    In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

  • CVE-2018-10915HigAug 9, 2018
    risk 0.56cvss 8.5epss 0.05

    A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could…

  • CVE-2015-3314HigSep 7, 2017
    risk 0.56cvss 8.1epss 0.05

    SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.

  • CVE-2016-0249HigOct 16, 2016
    risk 0.56cvss 8.6epss 0.01

    SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2026-66580HigSep 17, 2026
    risk 0.55cvss 8.5epss 0.00

    Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

  • CVE-2026-88890HigSep 10, 2026
    risk 0.55cvss 8.5epss 0.00

    OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export…

  • CVE-2026-81287HigAug 31, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

  • CVE-2026-82227HigAug 28, 2026
    risk 0.55cvss 8.5epss 0.00

    Contributor SQL Injection in WPBulky <= 1.2.2 versions.

  • CVE-2026-81277HigAug 27, 2026
    risk 0.55cvss 8.5epss 0.00

    Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

  • CVE-2026-78285HigAug 27, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.

  • CVE-2026-32564HigAug 27, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

  • CVE-2026-32550HigAug 27, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

  • CVE-2026-32478HigAug 24, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

  • CVE-2026-32471HigAug 24, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

  • CVE-2026-46682HigAug 20, 2026
    risk 0.55cvss 8.5epss 0.01

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutR…

  • CVE-2026-74013HigAug 20, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.

  • CVE-2026-73998HigAug 20, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.

  • CVE-2026-66594HigAug 20, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

  • CVE-2026-66668HigAug 19, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.