Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVE vulnerabilities with CWE-89 (24,122)
10.0
CVSS
CRITICAL
CVE-2026-74820
pub. 2026-08-27
10.0
CVSS
CRITICAL
CVE-2026-20030
pub. 2026-08-19
10.0
CVSS
CRITICAL
CVE-2026-72898
pub. 2026-08-10🚩 CISA KEV⚡ EXPLOIT
10.0
CVSS
CRITICAL
CVE-2026-72899
pub. 2026-08-10
10.0
CVSS
CRITICAL
CVE-2026-48330
pub. 2026-08-03
10.0
CVSS
CRITICAL
CVE-2026-52887
pub. 2026-07-15
10.0
CVSS
CRITICAL
CVE-2026-54350
pub. 2026-06-26
10.0
CVSS
CRITICAL
CVE-2026-8054
pub. 2026-05-27
10.0
CVSS
CRITICAL
CVE-2026-42287
pub. 2026-05-08
10.0
CVSS
CRITICAL
CVE-2026-3325
pub. 2026-04-29
10.0
CVSS
CRITICAL
CVE-2025-10878
pub. 2026-02-03
10.0
CVSS
CRITICAL
CVE-2025-57792
pub. 2026-01-28
10.0
CVSS
CRITICAL
CVE-2025-52694
pub. 2026-01-12
10.0
CVSS
CRITICAL
CVE-2025-65091
pub. 2026-01-10
10.0
CVSS
CRITICAL
CVE-2024-57521
pub. 2025-12-23
10.0
CVSS
CRITICAL
CVE-2025-63531
pub. 2025-12-01
10.0
CVSS
CRITICAL
CVE-2025-63689
pub. 2025-11-07
10.0
CVSS
CRITICAL
CVE-2025-57870
pub. 2025-10-22
10.0
CVSS
CRITICAL
CVE-2025-57819
pub. 2025-08-28🚩 CISA KEV⚡ EXPLOIT
10.0
CVSS
CRITICAL
CVE-2025-50567
pub. 2025-08-19
Showing 20 of 24,122 vulnerabilities