CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 360 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66630 | Hig | 0.49 | 7.6 | 0.00 | Sep 17, 2026 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | ||
| CVE-2026-66626 | Hig | 0.49 | 7.6 | 0.00 | Sep 17, 2026 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | ||
| CVE-2026-66625 | Hig | 0.49 | 7.6 | 0.00 | Sep 17, 2026 | Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. | ||
| CVE-2026-66624 | Hig | 0.49 | 7.6 | 0.00 | Sep 17, 2026 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | ||
| CVE-2026-66619 | Hig | 0.49 | 7.6 | 0.00 | Sep 17, 2026 | Administrator SQL Injection in Newsletters <= 4.18 versions. | ||
| CVE-2026-66618 | Hig | 0.49 | 7.6 | 0.00 | Sep 17, 2026 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | ||
| CVE-2026-76425 | Hig | 0.49 | 7.6 | 0.00 | Sep 16, 2026 | A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query.… | ||
| CVE-2026-20247 | Hig | 0.49 | 7.5 | 0.00 | Sep 16, 2026 | A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted… | ||
| CVE-2026-92465 | Hig | 0.49 | 7.6 | 0.00 | Sep 16, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2. | ||
| CVE-2026-89180 | Hig | 0.49 | 7.5 | 0.01 | Sep 14, 2026 | EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | ||
| CVE-2026-62112 | Hig | 0.49 | 7.6 | 0.00 | Sep 11, 2026 | Editor SQL Injection in Amelia <= 2.4.9 versions. | ||
| CVE-2026-62109 | Hig | 0.49 | 7.6 | 0.00 | Sep 11, 2026 | Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions. | ||
| CVE-2026-72708 | Hig | 0.49 | 7.5 | 0.01 | Sep 11, 2026 | SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which… | ||
| CVE-2026-15462 | Hig | 0.49 | 7.5 | 0.00 | Sep 11, 2026 | The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled… | ||
| CVE-2026-78837 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2026 | A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement. | ||
| CVE-2026-82527 | Hig | 0.49 | 7.5 | 0.00 | Sep 3, 2026 | R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter key parameter in the retrieval search endpoint. Attackers can exploit the direct interpolation of… | ||
| CVE-2026-85155 | Hig | 0.49 | 7.5 | 0.00 | Sep 3, 2026 | WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can… | ||
| CVE-2026-5097 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | ||
| CVE-2026-18884 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | ||
| CVE-2026-78270 | Hig | 0.49 | 7.6 | 0.00 | Aug 24, 2026 | Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. |
- risk 0.49cvss 7.6epss 0.00
Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
- risk 0.49cvss 7.6epss 0.00
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
- risk 0.49cvss 7.6epss 0.00
Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
- risk 0.49cvss 7.6epss 0.00
Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
- risk 0.49cvss 7.6epss 0.00
Administrator SQL Injection in Newsletters <= 4.18 versions.
- risk 0.49cvss 7.6epss 0.00
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
- risk 0.49cvss 7.6epss 0.00
A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query.…
- risk 0.49cvss 7.5epss 0.00
A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted…
- risk 0.49cvss 7.6epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.
- risk 0.49cvss 7.5epss 0.01
EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
- risk 0.49cvss 7.6epss 0.00
Editor SQL Injection in Amelia <= 2.4.9 versions.
- risk 0.49cvss 7.6epss 0.00
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
- risk 0.49cvss 7.5epss 0.01
SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which…
- risk 0.49cvss 7.5epss 0.00
The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled…
- risk 0.49cvss 7.5epss 0.00
A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.
- risk 0.49cvss 7.5epss 0.00
R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter key parameter in the retrieval search endpoint. Attackers can exploit the direct interpolation of…
- risk 0.49cvss 7.5epss 0.00
WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can…
- risk 0.49cvss 7.5epss 0.01
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
- risk 0.49cvss 7.5epss 0.00
The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
- risk 0.49cvss 7.6epss 0.00
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.