The product uses a database table that includes records that should not be accessible to an actor, but it executes a SQL statement with a primary key that can be controlled by that actor.
Volume of CVEs assigned to CWE-566 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9953CRITICAL Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection.
This | Feb 19, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-61781CRITICAL OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "WorkspacePopoverDeletionMutation" | Jan 5, 2026 | 9.1 | 29 | NO | NO |
CVE-2014-0808CRITICAL Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is explo | Jan 22, 2014 | 9.1 | 28 | NO | NO |
CVE-2026-21886HIGH OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.9.1, the GraphQL mutations "IndividualDeletionDeleteMutation | Mar 17, 2026 | 8.1 | 26 | NO | NO |
An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - | Sep 11, 2025 | 3.8 | 17 | NO | NO |
CVE-2024-22261MEDIUM SQL-Injection in Harbor allows priviledge users to leak the task IDs | Jun 11, 2024 | 5.5 | 17 | NO | NO |
Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to | Mar 31, 2025 | 2.7 | 13 | NO | NO |
Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its hand | Mar 31, 2025 | 2.7 | 12 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.