CWE-89— SQL Injection
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.— MITRE CWE catalog
21,099 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-89page 5 of 422
- CVE-2026-108107CRITICALCVSS 9.8EG 9.82026-10-09
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or n…
- CVE-2026-80381CRITICALCVSS 9.8EG 9.82026-10-08
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due to SQL injection.
- CVE-2026-105845CRITICALCVSS 9.8EG 9.82026-10-06
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins ca…
- CVE-2026-88395CRITICALCVSS 9.8EG 9.82026-10-05
GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.
- CVE-2026-88424CRITICALCVSS 9.8EG 9.82026-10-05
FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statement…
- CVE-2026-18782CRITICALCVSS 9.8EG 9.82026-09-30
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES:…
- CVE-2026-82307CRITICALCVSS 9.8EG 9.82026-09-30
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
- CVE-2023-54400CRITICALCVSS 9.8EG 9.82026-09-29
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authenticat…
- CVE-2026-101110CRITICALCVSS 9.8EG 9.82026-09-28
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectIn…
- CVE-2025-63564CRITICALCVSS 9.8EG 9.82026-09-23
SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests
- CVE-2026-12718CRITICALCVSS 9.8EG 9.82026-09-22
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The v…
- CVE-2026-88414CRITICALCVSS 9.8EG 9.82026-09-22
MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do).
- CVE-2026-88416CRITICALCVSS 9.8EG 9.82026-09-22
MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.
- CVE-2026-88402CRITICALCVSS 9.8EG 9.82026-09-21
A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.
- CVE-2026-84082CRITICALCVSS 9.8EG 9.82026-09-18
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
- CVE-2026-80441CRITICALCVSS 9.8EG 9.82026-09-18
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subseq…
- CVE-2023-54399CRITICALCVSS 9.8EG 9.82026-09-18
Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthenticate…
- CVE-2026-67100CRITICALCVSS 9.8EG 9.82026-09-18
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as …
- CVE-2025-55787CRITICALCVSS 9.8EG 9.82026-09-17
In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
- CVE-2026-87184CRITICALCVSS 9.8EG 9.82026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2024-58385CRITICALCVSS 9.8EG 9.82026-09-15
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries …
- CVE-2026-77051CRITICALCVSS 9.8EG 9.82026-09-14
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…
- CVE-2026-82232CRITICALCVSS 9.8EG 9.82026-09-14
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging uns…
- CVE-2026-86460CRITICALCVSS 9.8EG 9.82026-09-14
Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Us…
- CVE-2026-52630CRITICALCVSS 9.8EG 9.82026-09-11
SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php
- CVE-2026-9163CRITICALCVSS 9.8EG 9.82026-09-10
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1…
- CVE-2026-7188CRITICALCVSS 9.8EG 9.82026-09-10
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Ve…
- CVE-2026-38626CRITICALCVSS 9.8EG 9.82026-09-10
Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.
- CVE-2026-77098CRITICALCVSS 9.8EG 9.82026-09-08
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
- CVE-2026-79569CRITICALCVSS 9.8EG 9.82026-09-08
Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
- CVE-2026-79570CRITICALCVSS 9.8EG 9.82026-09-08
mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
- CVE-2026-18658CRITICALCVSS 9.8EG 9.82026-09-04
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to w…
- CVE-2025-67066CRITICALCVSS 9.8EG 9.82026-09-04
SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path
- CVE-2026-82526CRITICALCVSS 9.8EG 9.82026-09-03
R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is in…
- CVE-2026-18210CRITICALCVSS 9.8EG 9.82026-09-01
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This i…
- CVE-2026-18765CRITICALCVSS 9.8EG 9.82026-09-01
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.
- CVE-2026-68000CRITICALCVSS 9.8EG 9.82026-08-26
The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built…
- CVE-2026-75330CRITICALCVSS 9.8EG 9.82026-08-26
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() a…
- CVE-2026-75334CRITICALCVSS 9.8EG 9.82026-08-26
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded …
- CVE-2026-75336CRITICALCVSS 9.8EG 9.82026-08-26
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
- CVE-2026-76904CRITICALCVSS 9.8EG 9.82026-08-21
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataSto…
- CVE-2026-63039CRITICALCVSS 9.8EG 9.82026-08-20
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects A…
- CVE-2026-63038CRITICALCVSS 9.8EG 9.82026-08-20
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters. …
- CVE-2026-63037CRITICALCVSS 9.8EG 9.82026-08-20
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apac…
- CVE-2026-77071CRITICALCVSS 9.8EG 9.82026-08-20
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value withou…
- CVE-2026-16019CRITICALCVSS 9.8EG 9.82026-08-19
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0.
- CVE-2026-50769CRITICALCVSS 9.8EG 9.82026-08-17
The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=tru…
- CVE-2026-67854CRITICALCVSS 9.8EG 9.82026-08-17
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
- CVE-2026-67917CRITICALCVSS 9.8EG 9.82026-08-17
zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validati…
- CVE-2026-48528CRITICALCVSS 9.8EG 9.82026-08-14
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API …
Map vulnerabilities like CWE-89 to your infrastructure
EchelonGraph correlates every CVE — across CWE-89 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →