External resources 03References NVD — National Vulnerability Database https://nvd.nist.gov/vuln/detail/CVE-2023-40629 CWE — Common Weakness Enumeration https://cwe.mitre.org/data/definitions/89.html AskarLabs — CWE-89 write-up SQL Injection
Related vulnerabilities 04Related CVE CVE-2026-74251 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 CVE-2026-2497 Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys CVE-2026-66472 WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability CVE-2026-18387 Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter CVE-2026-28156 WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability