CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,200)
page 922 of 1,010| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-63359 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and… | ||
| CVE-2026-65761 | Cri | 0.00 | — | 0.00 | Jul 23, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions. | ||
| CVE-2026-65532 | Hig | 0.00 | 7.6 | 0.00 | Jul 23, 2026 | Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | ||
| CVE-2026-65526 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1. | ||
| CVE-2026-65494 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | ||
| CVE-2026-65462 | Hig | 0.00 | 7.6 | 0.00 | Jul 23, 2026 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. | ||
| CVE-2026-65454 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | ||
| CVE-2026-65451 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-65450 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-61950 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | ||
| CVE-2026-61949 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | ||
| CVE-2026-61948 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. | ||
| CVE-2026-59526 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-59525 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | ||
| CVE-2026-59514 | Cri | 0.00 | 9.3 | 0.00 | Jul 23, 2026 | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. | ||
| CVE-2026-25405 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in eRoom <= 1.7.1 versions. | ||
| CVE-2026-15906 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-15761 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-15448 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2026-13119 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from… |
- risk 0.00cvss 9.8epss 0.00
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and…
- risk 0.00cvss —epss 0.00
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.
- risk 0.00cvss 7.6epss 0.00
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
- risk 0.00cvss 8.5epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.
- risk 0.00cvss 7.1epss 0.00
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
- risk 0.00cvss 7.6epss 0.00
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in eRoom <= 1.7.1 versions.
- risk 0.00cvss 6.5epss 0.00
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.00cvss 6.5epss 0.00
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.00cvss 6.5epss 0.00
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.00cvss 6.5epss 0.00
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from…