CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,858)
page 297 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32552 | Hig | 0.55 | 8.5 | 0.00 | Aug 19, 2026 | Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | ||
| CVE-2026-32466 | Hig | 0.55 | 8.5 | 0.00 | Aug 18, 2026 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | ||
| CVE-2026-66658 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | ||
| CVE-2026-66430 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||
| CVE-2026-28168 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | ||
| CVE-2026-28156 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Subscriber SQL Injection in Do Lasso <= 358 versions. | ||
| CVE-2026-28002 | Hig | 0.55 | 8.5 | 0.00 | Aug 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22. | ||
| CVE-2026-73300 | Cri | 0.55 | 9.6 | 0.01 | Aug 12, 2026 | Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input… | ||
| CVE-2026-17418 | Hig | 0.55 | 8.5 | 0.00 | Aug 12, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command. | ||
| CVE-2026-65569 | Hig | 0.55 | 8.5 | 0.00 | Aug 6, 2026 | Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. | ||
| CVE-2026-65547 | Hig | 0.55 | 8.5 | 0.00 | Aug 6, 2026 | Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | ||
| CVE-2026-24552 | Hig | 0.55 | 8.5 | 0.00 | Jul 23, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create mediavine-create allows Blind SQL Injection.This issue affects Create: from n/a through 2.5.3. | ||
| CVE-2025-69094 | Hig | 0.55 | 8.5 | 0.00 | Jul 2, 2026 | Subscriber SQL Injection in Unicamp <= 2.2.2 versions. | ||
| CVE-2026-54185 | Hig | 0.55 | 8.5 | 0.00 | Jun 17, 2026 | Subscriber SQL Injection in Cornerstone < 7.8.8 versions. | ||
| CVE-2026-49073 | Hig | 0.55 | 8.5 | 0.00 | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3. | ||
| CVE-2026-48967 | Hig | 0.55 | 8.5 | 0.00 | Jun 17, 2026 | Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions. | ||
| CVE-2026-22335 | Hig | 0.55 | 8.5 | 0.00 | Jun 17, 2026 | Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. | ||
| CVE-2025-69135 | Hig | 0.55 | 8.5 | 0.00 | Jun 17, 2026 | Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions. | ||
| CVE-2026-39581 | Hig | 0.55 | 8.5 | 0.00 | Jun 16, 2026 | Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. | ||
| CVE-2026-52700 | Hig | 0.55 | 8.5 | 0.00 | Jun 15, 2026 | Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. |
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Do Lasso <= 358 versions.
- risk 0.55cvss 8.5epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22.
- risk 0.55cvss 9.6epss 0.01
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input…
- risk 0.55cvss 8.5epss 0.00
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
- risk 0.55cvss 8.5epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create mediavine-create allows Blind SQL Injection.This issue affects Create: from n/a through 2.5.3.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
- risk 0.55cvss 8.5epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
- risk 0.55cvss 8.5epss 0.00
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.