CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,572 vulnerabilities with CWE-89
CVE-2025-52040
HIGH
Frappe ERPNext 15.57.5 - SQL Injection via blanket_order_type Parameter
CVSS 8.2
CVE-2025-52039
HIGH
Frappe ERPNext 15.57.5 - SQL Injection via txt Parameter in get_material_requests_based_on_supplier()
CVSS 8.2
CVE-2025-57254
MEDIUM
Karthikg1908 HMS 1.0 - SQL Injection
CVSS 6.5
CVE-2025-52050
MEDIUM
Frappe ERPNext 15.57.5 - SQL Injection via Loyalty Program Expiry Date Parameter
CVSS 6.5
CVE-2025-52049
MEDIUM
Frappe ErpNext v15.57.5 - SQL Injection via timelog Parameter in get_timesheet_detail_rate()
CVSS 6.5
CVE-2025-52047
MEDIUM
Frappe ErpNext v15.57.5 - SQL Injection via filters.disabled Parameter
CVSS 6.5
CVE-2025-52043
MEDIUM
Frappe ERPNext v15.57.5 - SQL Injection via import_coa() company parameter
CVSS 6.5
CVE-2025-8877
HIGH
AffiliateWP <2.28.2 - SQL Injection
CVSS 7.5
CVE-2025-8122
HIGH
widzialni pad_cms < 1.2.1 - Authenticated Blind SQL Injection in Article Positioning
CVSS 8.8
CVE-2025-8121
HIGH
widzialni pad_cms < 1.2.1 - Authenticated Blind SQL Injection in Article Positioning
CVSS 8.8
CVE-2025-8868
CRITICAL
Chef Automate < 4.13.295 - Authenticated Exposure of Sensitive Information via SQL Command Injection
CVSS 9.8
CVE-2025-6724
HIGH
Chef Automate < 4.13.295 - Authenticated SQL Injection
CVSS 8.8
CVE-2025-11118
HIGH
CodeAstro Student Grading System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11116
HIGH
code-projects Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11115
HIGH
code-projects Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11114
MEDIUM
CodeAstro Online Leave Application 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11113
MEDIUM
CodeAstro Online Leave Application 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11111
HIGH
Campcodes Advanced Online Voting Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11110
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11109
HIGH
Campcodes Computer Sales & Inventory System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11108
HIGH
Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11107
HIGH
Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11106
HIGH
Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11105
HIGH
Code-projects Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11104
MEDIUM
CodeAstro Electricity Billing System 1.0 - SQL Injection
CVSS 6.3
Details
Vulnerabilities
19,572
Exploit Likelihood
High