VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 362 of 1,044
  • CVE-2025-61028HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2025-61027HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2025-61025HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2025-61021HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2025-61019HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2025-61018HigJun 23, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2026-40455HigJun 18, 2026
    risk 0.49cvss —epss 0.00

    An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" module due to insufficient sanitization of the POST "tg[]" parameter. The application directly concatenates user-supplied array values into an SQL query using…

  • CVE-2026-12360HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter…

  • CVE-2026-52712HigJun 16, 2026
    risk 0.49cvss 7.6epss 0.00

    Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.

  • CVE-2026-40762HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.

  • CVE-2026-6428HigJun 13, 2026
    risk 0.49cvss 7.6epss 0.00

    SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag…

  • CVE-2026-49771HigJun 4, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.

  • CVE-2025-15655HigJun 3, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0.

  • CVE-2026-5073HigJun 2, 2026
    risk 0.49cvss 7.5epss 0.02

    The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby'…

  • CVE-2026-24782HigJun 1, 2026
    risk 0.49cvss 7.6epss 0.01

    Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify other users' form definitions and…

  • CVE-2026-40850HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

  • CVE-2026-40819HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

  • CVE-2026-40818HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevice function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

  • CVE-2026-40817HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

  • CVE-2026-40816HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.