VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,200)

page 922 of 1,010
  • CVE-2026-63359CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and…

  • CVE-2026-65761CriJul 23, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.

  • CVE-2026-65532HigJul 23, 2026
    risk 0.00cvss 7.6epss 0.00

    Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

  • CVE-2026-65526HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

  • CVE-2026-65494HigJul 23, 2026
    risk 0.00cvss 7.1epss 0.00

    Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.

  • CVE-2026-65462HigJul 23, 2026
    risk 0.00cvss 7.6epss 0.00

    Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

  • CVE-2026-65454HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

  • CVE-2026-65451HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in MapSVG <= 8.14.0 versions.

  • CVE-2026-65450HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in MapSVG <= 8.14.0 versions.

  • CVE-2026-61950CriJul 23, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

  • CVE-2026-61949CriJul 23, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Bookly <= 27.7 versions.

  • CVE-2026-61948CriJul 23, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

  • CVE-2026-59526CriJul 23, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

  • CVE-2026-59525CriJul 23, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

  • CVE-2026-59514CriJul 23, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

  • CVE-2026-25405HigJul 23, 2026
    risk 0.00cvss 8.5epss 0.00

    Contributor SQL Injection in eRoom <= 1.7.1 versions.

  • CVE-2026-15906MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15761MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15448MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-13119MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from…