VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 568 of 1,044
  • CVE-2026-92903HigSep 17, 2026
    risk 0.46cvss 8.2epss 0.00

    Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a malicious project configuration file or craft…

  • CVE-2026-20300HigSep 16, 2026
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to improper…

  • CVE-2026-85388HigSep 3, 2026
    risk 0.46cvss 8.1epss 0.00

    Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection…

  • CVE-2026-81728HigAug 27, 2026
    risk 0.46cvss 8.1epss 0.00

    Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords,…

  • CVE-2026-56088HigAug 19, 2026
    risk 0.46cvss 7.1epss 0.00

    Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script…

  • CVE-2026-73345HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.

  • CVE-2026-16007HigAug 15, 2026
    risk 0.46cvss —epss 0.00

    AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.

  • CVE-2026-19680HigAug 14, 2026
    risk 0.46cvss 7.1epss 0.00

    A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.

  • CVE-2026-72609HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_receive permission to read arbitrary database contents via the orderby request parameter in acqui/parcels.pl. The parameter is…

  • CVE-2026-72607HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary database contents by storing a SQL payload in the agefield value of an automatic item…

  • CVE-2026-66838HigAug 7, 2026
    risk 0.46cvss 8.2epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and…

  • CVE-2026-71276HigAug 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf in both the PostgreSQL reader (readers/postgres/messages.go: ) and…

  • CVE-2026-64880HigJul 21, 2026
    risk 0.46cvss 7.1epss 0.00

    Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.

  • CVE-2026-47255HigJul 20, 2026
    risk 0.46cvss 8.2epss 0.00

    AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation;…

  • CVE-2026-57821HigJul 15, 2026
    risk 0.46cvss 8.1epss 0.01

    A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission…

  • CVE-2026-56287HigJul 15, 2026
    risk 0.46cvss 8.1epss 0.01

    A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an…

  • CVE-2026-40524HigJun 29, 2026
    risk 0.46cvss 8.1epss 0.00

    FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN() clause without parameterization. Attackers with SA_GLANALYTIC permission can inject arbitrary SQL…

  • CVE-2026-40523HigJun 29, 2026
    risk 0.46cvss 8.1epss 0.00

    FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authenticated attackers with SA_GLANALYTIC permission to execute arbitrary SQL queries by injecting malicious code into the PARAM_2 and PARAM_3 POST parameters.…

  • CVE-2026-56351HigJun 24, 2026
    risk 0.46cvss 8.2epss 0.00

    n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation…

  • CVE-2025-66336HigJun 22, 2026
    risk 0.46cvss 8.1epss 0.01

    Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated…