CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-40885 MEDIUM
Nozomi Networks CMC and Guardian < 25.2.0 - Authenticated SQL Injection via Smart Polling Input Parameter
CVSS 5.3
CVE-2025-11396 HIGH
Simple Food Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-0603 CRITICAL
Callvision Emergency Code <V3.0 - SQL Injection
CVSS 9.8
CVE-2025-11359 MEDIUM
Simple Banking System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11358 MEDIUM
Code-projects Simple Banking System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11357 MEDIUM
Simple Banking System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11350 HIGH
Campcodes Online Apartment Visitor Management System 1.0 - SQL Injection via fromdate/todate Parameter
CVSS 7.3
CVE-2025-11349 HIGH
Campcodes Online Apartment Visitor Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-11348 HIGH
Campcodes Online Apartment Visitor Management System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-57515 CRITICAL
Uniclare Student Portal <v2 - SQL Injection
CVSS 9.8
CVE-2025-11343 HIGH
code-projects Student Crud Operation <3.3 - SQL Injection
CVSS 7.3
CVE-2025-11342 MEDIUM
Code-projects Online Course Registration 1.0 - SQL Injection
CVSS 4.7
CVE-2025-52472 CRITICAL
XWiki Platform 4.3-milestone-1-16.10.8, 17.0.0-rc-1-17.4.1 - SQL Injection via REST Search orderField Parameter
CVE-2025-11334 HIGH
Campcodes Online Apartment Visitor Management System 1.0 - SQL Injection via editid Parameter
CVSS 7.3
CVE-2025-11330 MEDIUM
PHPGurukul Beauty Parlour Management System 1.1 - SQL Injection
CVSS 6.3
CVE-2025-11329 HIGH
Code-Projects Online Course Registration <1.0 - SQL Injection
CVSS 7.3
CVE-2025-11319 MEDIUM
nahiduddinahammed Hospital-Management-System-Website <e6562429e14b2...
CVSS 6.3
CVE-2025-11317 HIGH
Tipray Data Leakage Prevention System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11316 HIGH
Tipray Data Leakage Prevention System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11315 HIGH
Tipray Data Leakage Prevention System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11314 HIGH
Tipray Data Leakage Prevention System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11313 HIGH
Tipray Data Leakage Prevention System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11312 HIGH
Tipray Data Leakage Prevention System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11311 HIGH
Tipray Data Leakage Prevention System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11310 HIGH
Tipray Data Leakage Prevention System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,572
Exploit Likelihood High