VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 361 of 1,044
  • CVE-2026-74011HigAug 20, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.

  • CVE-2026-76240HigAug 19, 2026
    risk 0.49cvss —epss 0.00

    stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant,…

  • CVE-2026-66622HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.

  • CVE-2026-15162HigAug 15, 2026
    risk 0.49cvss 7.5epss 0.01

    The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push…

  • CVE-2026-16961HigAug 13, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2024-58374HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet…

  • CVE-2019-25765HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.01

    ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword…

  • CVE-2026-73346HigAug 13, 2026
    risk 0.49cvss 7.6epss 0.00

    Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.

  • CVE-2026-27538HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

  • CVE-2026-17111HigAug 12, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2022-50997HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a…

  • CVE-2016-20097HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a…

  • CVE-2026-18881HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This is due to insufficient…

  • CVE-2026-15918HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper…

  • CVE-2026-50736HigJul 28, 2026
    risk 0.49cvss 7.5epss 0.00

    The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default…

  • CVE-2026-55405HigJul 10, 2026
    risk 0.49cvss 7.6epss 0.00

    LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string…

  • CVE-2026-56052HigJun 24, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5.

  • CVE-2026-9179HigJun 24, 2026
    risk 0.49cvss 7.5epss 0.01

    The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from…

  • CVE-2026-8705HigJun 24, 2026
    risk 0.49cvss 7.5epss 0.01

    The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions up to, and including, 3.4.2. The handler is registered for unauthenticated users…

  • CVE-2025-61029HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.