VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,200)

page 939 of 1,010
  • CVE-2026-54843CriJun 25, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

  • CVE-2026-54838HigJun 25, 2026
    risk 0.00cvss 8.5epss 0.00

    Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

  • CVE-2026-54836CriJun 25, 2026
    risk 0.00cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5.

  • CVE-2026-54829HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005.

  • CVE-2026-54822HigJun 25, 2026
    risk 0.00cvss 8.5epss 0.00

    Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

  • CVE-2026-12937HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and including, 2.22.7 due to insufficient escaping on the user supplied parameter…

  • CVE-2026-2508MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2026-12079MedJun 25, 2026
    risk 0.00cvss 6.5epss 0.00

    The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

  • CVE-2026-12077HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2025-61029HigJun 23, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2025-61024HigJun 23, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2026-34914HigJun 23, 2026
    risk 0.00cvss 8.3epss 0.00

    A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters…

  • CVE-2025-61025HigJun 23, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2025-61022HigJun 23, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2026-56012HigJun 18, 2026
    risk 0.00cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35.

  • CVE-2026-54222HigJun 18, 2026
    risk 0.00cvss epss 0.00

    UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to interact with the underlying database. Due to insufficient input sanitization, an attacker can extract sensitive information, such as user credentials, by…

  • CVE-2026-54812CriJun 17, 2026
    risk 0.00cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4.109.

  • CVE-2026-54819CriJun 17, 2026
    risk 0.00cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.

  • CVE-2026-54818HigJun 17, 2026
    risk 0.00cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimstat Analytics allows Blind SQL Injection. This issue affects Slimstat Analytics: from n/a through 5.4.11.

  • CVE-2026-54815CriJun 17, 2026
    risk 0.00cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.