VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 360 of 1,044
  • CVE-2026-66630HigSep 17, 2026
    risk 0.49cvss 7.6epss 0.00

    Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

  • CVE-2026-66626HigSep 17, 2026
    risk 0.49cvss 7.6epss 0.00

    Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

  • CVE-2026-66625HigSep 17, 2026
    risk 0.49cvss 7.6epss 0.00

    Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

  • CVE-2026-66624HigSep 17, 2026
    risk 0.49cvss 7.6epss 0.00

    Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

  • CVE-2026-66619HigSep 17, 2026
    risk 0.49cvss 7.6epss 0.00

    Administrator SQL Injection in Newsletters <= 4.18 versions.

  • CVE-2026-66618HigSep 17, 2026
    risk 0.49cvss 7.6epss 0.00

    Administrator SQL Injection in WP Maps <= 4.9.9 versions.

  • CVE-2026-76425HigSep 16, 2026
    risk 0.49cvss 7.6epss 0.00

    A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query.…

  • CVE-2026-20247HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted…

  • CVE-2026-92465HigSep 16, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

  • CVE-2026-89180HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.01

    EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

  • CVE-2026-62112HigSep 11, 2026
    risk 0.49cvss 7.6epss 0.00

    Editor SQL Injection in Amelia <= 2.4.9 versions.

  • CVE-2026-62109HigSep 11, 2026
    risk 0.49cvss 7.6epss 0.00

    Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.

  • CVE-2026-72708HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.01

    SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which…

  • CVE-2026-15462HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled…

  • CVE-2026-78837HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-82527HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter key parameter in the retrieval search endpoint. Attackers can exploit the direct interpolation of…

  • CVE-2026-85155HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can…

  • CVE-2026-5097HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2026-18884HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2026-78270HigAug 24, 2026
    risk 0.49cvss 7.6epss 0.00

    Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.