CWE-89 SQL命令中使用的特殊元素转义处理不恰当(SQL注入) 类弱点 10094 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-89即SQL注入,属于输入验证类漏洞。当软件未对用户输入进行充分净化或转义,直接将其拼接到SQL命令中时,攻击者可注入恶意SQL代码,从而篡改查询逻辑、绕过身份验证或窃取敏感数据。开发者应避免直接拼接字符串,转而使用参数化查询或预编译语句,确保用户输入仅被视为数据而非可执行代码,从而从根本上阻断注入路径。
... string userName = ctx.getAuthenticatedUserName(); string query = "SELECT * FROM items WHERE owner = '" + userName + "' AND itemname = '" + ItemName.Text + "'"; sda = new SqlDataAdapter(query, conn); DataTable dt = new DataTable(); sda.Fill(dt); ...SELECT * FROM items WHERE owner = <userName> AND itemname = <itemName>;| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-13161 | WordPress TrueBooker SQL注入漏洞 — TrueBooker – Appointment Booking and Scheduler System | 7.5 | High | 2026-07-28 |
| CVE-2026-14516 | WordPress Bookly SQL注入漏洞 — Online Scheduling and Appointment Booking System – Bookly | 7.5 | High | 2026-07-28 |
| CVE-2026-12741 | WordPress WP Fast Total Search SQL注入漏洞 — WP Fast Total Search – The Power of Indexed Search | 7.5 | High | 2026-07-28 |
| CVE-2026-15670 | WordPress SMS Alert SQL注入漏洞 — SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | 4.9 | Medium | 2026-07-28 |
| CVE-2026-15673 | WordPress SMS Alert SQL注入漏洞 — SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | 4.4 | Medium | 2026-07-28 |
| CVE-2026-15671 | WordPress SMS Alert SQL注入漏洞 — SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery | 4.9 | Medium | 2026-07-28 |
| CVE-2026-16811 | WordPress ShopLentor SQL注入漏洞 — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | 4.9 | Medium | 2026-07-28 |
| CVE-2026-6251 | WordPress Chaty Pro SQL注入漏洞 — Chaty Pro | 6.5 | Medium | 2026-07-28 |
| CVE-2026-17191 | VeloCloud Orchestrator Flow Metrics API SQL注入漏洞 — VeloCloud Orchestrator On-Prem | 9.1 | Critical | 2026-07-27 |
| CVE-2026-66427 | WordPress WP Google Review Slider SQL注入漏洞 — WP Google Review Slider | 7.6 | High | 2026-07-27 |
| CVE-2026-59550 | Strategy11 Team AWP Classifieds SQL注入漏洞 — AWP Classifieds | 9.3 | Critical | 2026-07-27 |
| CVE-2026-59551 | WordPress rtMedia SQL注入漏洞 — rtMedia for WordPress, BuddyPress and bbPress | 8.5 | High | 2026-07-27 |
| CVE-2026-59549 | WordPress rtMedia SQL注入漏洞 — rtMedia for WordPress, BuddyPress and bbPress | 9.3 | Critical | 2026-07-27 |
| CVE-2026-59538 | Ruben Garcia GamiPress SQL注入漏洞 — GamiPress | 9.3 | Critical | 2026-07-27 |
| CVE-2026-59537 | WordPress Sender SQL注入漏洞 — Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | 7.6 | High | 2026-07-27 |
| CVE-2026-59533 | WordPress Relevanssi Light SQL注入漏洞 — Relevanssi Light | 9.3 | Critical | 2026-07-27 |
| CVE-2026-59527 | WordPress MapSVG SQL注入漏洞 — MapSVG | 9.3 | Critical | 2026-07-27 |
| CVE-2026-65876 | JoomShaper SP Page Builder SQL注入漏洞 — SP Page Builder extension for Joomla | 9.2 | Critical | 2026-07-27 |
| CVE-2026-65877 | JoomShaper SP Page Builder SQL注入漏洞 — SP Page Builder extension for Joomla | 8.2 | High | 2026-07-27 |
| CVE-2026-65766 | JoomShaper SP Page Builder SQL注入漏洞 — SP Page Builder extension for Joomla | 9.2 | Critical | 2026-07-27 |
| CVE-2026-65707 | Likeshop SQL注入漏洞 — likeshop | 6.5 | Medium | 2026-07-24 |
| CVE-2026-15663 | WordPress Ninja Forms SQL注入漏洞 — Ninja Forms – The Contact Form Builder That Grows With You | 4.9 | Medium | 2026-07-24 |
| CVE-2026-16765 | CodeAstro Online Classroom 输入验证错误漏洞 — Online Classroom | 7.3 | High | 2026-07-23 |
| CVE-2026-63359 | Appriss Insights Victim Information Notification Exchange SQL注入漏洞 — Victim Information Notification Exchange (VINE) | 9.8 | Critical | 2026-07-23 |
| CVE-2026-65761 | JoomShaper EasyStore SQL注入漏洞 — Easy Store extension for Joomla | 9.3 | Critical | 2026-07-23 |
| CVE-2026-65532 | WordPress Persian Woocommerce SMS SQL注入漏洞 — Persian Woocommerce SMS | 7.6 | High | 2026-07-23 |
| CVE-2026-65526 | themeisle visualizer SQL注入漏洞 — Visualizer | 8.5 | High | 2026-07-23 |
| CVE-2026-65494 | Dokan Pro SQL注入漏洞 — Dokan Pro | 7.1 | High | 2026-07-23 |
| CVE-2026-65462 | WordPress Uncanny Automator SQL注入漏洞 — Uncanny Automator | 7.6 | High | 2026-07-23 |
| CVE-2026-65454 | expresstech quiz and survey master SQL注入漏洞 — Quiz And Survey Master | 8.5 | High | 2026-07-23 |
CWE-89(SQL命令中使用的特殊元素转义处理不恰当(SQL注入)) 是常见的弱点类别,本平台收录该类弱点关联的 10094 条 CVE 漏洞。