CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,858)
page 296 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26830 | Cri | 0.56 | 9.1 | 0.05 | Apr 16, 2021 | SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module. | ||
| CVE-2020-5504 | Hig | 0.56 | 8.8 | 0.39 | Jan 9, 2020 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server. | ||
| CVE-2018-10915 | Hig | 0.56 | 8.5 | 0.05 | Aug 9, 2018 | A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could… | ||
| CVE-2015-3314 | Hig | 0.56 | 8.1 | 0.05 | Sep 7, 2017 | SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. | ||
| CVE-2016-0249 | Hig | 0.56 | 8.6 | 0.01 | Oct 16, 2016 | SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | ||
| CVE-2026-66580 | Hig | 0.55 | 8.5 | 0.00 | Sep 17, 2026 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | ||
| CVE-2026-88890 | Hig | 0.55 | 8.5 | 0.00 | Sep 10, 2026 | OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export… | ||
| CVE-2026-81287 | Hig | 0.55 | 8.5 | 0.00 | Aug 31, 2026 | Subscriber SQL Injection in Charitable <= 1.8.12.1 versions. | ||
| CVE-2026-82227 | Hig | 0.55 | 8.5 | 0.00 | Aug 28, 2026 | Contributor SQL Injection in WPBulky <= 1.2.2 versions. | ||
| CVE-2026-81277 | Hig | 0.55 | 8.5 | 0.00 | Aug 27, 2026 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | ||
| CVE-2026-78285 | Hig | 0.55 | 8.5 | 0.00 | Aug 27, 2026 | Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions. | ||
| CVE-2026-32564 | Hig | 0.55 | 8.5 | 0.00 | Aug 27, 2026 | Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. | ||
| CVE-2026-32550 | Hig | 0.55 | 8.5 | 0.00 | Aug 27, 2026 | Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions. | ||
| CVE-2026-32478 | Hig | 0.55 | 8.5 | 0.00 | Aug 24, 2026 | Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions. | ||
| CVE-2026-32471 | Hig | 0.55 | 8.5 | 0.00 | Aug 24, 2026 | Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. | ||
| CVE-2026-46682 | Hig | 0.55 | 8.5 | 0.01 | Aug 20, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutR… | ||
| CVE-2026-74013 | Hig | 0.55 | 8.5 | 0.00 | Aug 20, 2026 | Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | ||
| CVE-2026-73998 | Hig | 0.55 | 8.5 | 0.00 | Aug 20, 2026 | Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. | ||
| CVE-2026-66594 | Hig | 0.55 | 8.5 | 0.00 | Aug 20, 2026 | Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||
| CVE-2026-66668 | Hig | 0.55 | 8.5 | 0.00 | Aug 19, 2026 | Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. |
- risk 0.56cvss 9.1epss 0.05
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module.
- risk 0.56cvss 8.8epss 0.39
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
- risk 0.56cvss 8.5epss 0.05
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could…
- risk 0.56cvss 8.1epss 0.05
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
- risk 0.56cvss 8.6epss 0.01
SQL injection vulnerability in IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- risk 0.55cvss 8.5epss 0.00
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
- risk 0.55cvss 8.5epss 0.00
OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export…
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
- risk 0.55cvss 8.5epss 0.00
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
- risk 0.55cvss 8.5epss 0.00
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
- risk 0.55cvss 8.5epss 0.01
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutR…
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.