VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 320 of 1,043
  • CVE-2026-14920HigAug 2, 2026
    risk 0.53cvss 8.2epss 0.00

    ## Summary

  • CVE-2026-15258HigJul 31, 2026
    risk 0.53cvss 8.1epss 0.00

    The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.

  • CVE-2026-15829HigJul 21, 2026
    risk 0.53cvss 8.1epss 0.00

    A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings…

  • CVE-2026-54831CriJun 26, 2026
    risk 0.53cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

  • CVE-2026-44271HigJun 22, 2026
    risk 0.53cvss 8.1epss 0.00

    Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2019-25756HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with…

  • CVE-2019-25755HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with…

  • CVE-2019-25754HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint…

  • CVE-2019-25753HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter. Attackers can send GET requests to index.php with the…

  • CVE-2019-25752HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the…

  • CVE-2019-25751HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch,…

  • CVE-2019-25750HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels…

  • CVE-2019-25748HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL…

  • CVE-2017-20282HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the…

  • CVE-2017-20281HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch…

  • CVE-2017-20280HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attackers can send GET requests to index.php with malicious pid values in the…

  • CVE-2017-20279HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to…

  • CVE-2017-20278HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL…

  • CVE-2017-20277HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL…

  • CVE-2017-20276HigJun 19, 2026
    risk 0.53cvss 8.2epss 0.00

    Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the type parameter. Attackers can send GET requests to index.php with the option=com_simgenealogy,…