VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 315 of 1,043
  • CVE-2023-1578HigMar 22, 2023
    risk 0.55cvss 8.8epss 0.63

    SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.

  • CVE-2023-0631HigMar 20, 2023
    risk 0.55cvss 8.8epss 0.60

    The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.

  • CVE-2022-23510CriDec 9, 2022
    risk 0.55cvss 9.6epss 0.01

    cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised…

  • CVE-2022-33960HigJul 22, 2022
    risk 0.55cvss 8.5epss 0.01

    Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.

  • CVE-2022-1258HigApr 14, 2022
    risk 0.55cvss 8.4epss 0.01

    A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database, potentially leading to command execution on the server.

  • CVE-2021-4088HigJan 24, 2022
    risk 0.55cvss 8.4epss 0.02

    SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to inject unfiltered SQL into the DLP part of the ePO database. This could lead to remote code…

  • CVE-2021-25076HigJan 24, 2022
    risk 0.55cvss 8.8epss 0.17

    The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected…

  • CVE-2021-31849HigNov 1, 2021
    risk 0.55cvss 8.4epss 0.01

    SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.

  • CVE-2021-32704HigJun 24, 2021
    risk 0.55cvss 8.5epss 0.01

    DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of DHIS2. This vulnerability affects the /api/trackedEntityInstances API endpoint in DHIS2 versions…

  • CVE-2020-25514HigSep 22, 2020
    risk 0.55cvss 8.4epss 0.01

    Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http:///lms/admin.php.

  • CVE-2019-11600HigMay 13, 2019
    risk 0.55cvss 8.1epss 0.80

    A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.

  • CVE-2015-8356HigApr 14, 2017
    risk 0.55cvss 8.0epss 0.03

    Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) xls_profile parameter to admin/mcart_xls_import.php or the (2) xls_iblock_id, (3) xls_iblock_section_id, (4)…

  • CVE-2026-82583HigSep 11, 2026
    risk 0.54cvss 8.3epss 0.00

    NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.

  • CVE-2026-87034HigSep 9, 2026
    risk 0.54cvss 8.3epss 0.00

    Tanium addressed a SQL injection vulnerability in Comply.

  • CVE-2026-71867CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories without safe encoding. This permits…

  • CVE-2026-71866CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema without safe encoding. This permits…

  • CVE-2026-73663CriAug 13, 2026
    risk 0.54cvss —epss 0.02

    FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An…

  • CVE-2026-63221CriJul 31, 2026
    risk 0.54cvss 9.4epss 0.01

    CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This…

  • CVE-2026-60137MedKEVJul 17, 2026
    risk 0.54cvss 5.9epss 0.06

    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

  • CVE-2026-54760CriJul 10, 2026
    risk 0.54cvss —epss 0.01

    Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) with a `sqlglot`…