CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-52040 HIGH
Frappe ERPNext 15.57.5 - SQL Injection via blanket_order_type Parameter
CVSS 8.2
CVE-2025-52039 HIGH
Frappe ERPNext 15.57.5 - SQL Injection via txt Parameter in get_material_requests_based_on_supplier()
CVSS 8.2
CVE-2025-57254 MEDIUM
Karthikg1908 HMS 1.0 - SQL Injection
CVSS 6.5
CVE-2025-52050 MEDIUM
Frappe ERPNext 15.57.5 - SQL Injection via Loyalty Program Expiry Date Parameter
CVSS 6.5
CVE-2025-52049 MEDIUM
Frappe ErpNext v15.57.5 - SQL Injection via timelog Parameter in get_timesheet_detail_rate()
CVSS 6.5
CVE-2025-52047 MEDIUM
Frappe ErpNext v15.57.5 - SQL Injection via filters.disabled Parameter
CVSS 6.5
CVE-2025-52043 MEDIUM
Frappe ERPNext v15.57.5 - SQL Injection via import_coa() company parameter
CVSS 6.5
CVE-2025-8877 HIGH
AffiliateWP <2.28.2 - SQL Injection
CVSS 7.5
CVE-2025-8122 HIGH
widzialni pad_cms < 1.2.1 - Authenticated Blind SQL Injection in Article Positioning
CVSS 8.8
CVE-2025-8121 HIGH
widzialni pad_cms < 1.2.1 - Authenticated Blind SQL Injection in Article Positioning
CVSS 8.8
CVE-2025-8868 CRITICAL
Chef Automate < 4.13.295 - Authenticated Exposure of Sensitive Information via SQL Command Injection
CVSS 9.8
CVE-2025-6724 HIGH
Chef Automate < 4.13.295 - Authenticated SQL Injection
CVSS 8.8
CVE-2025-11118 HIGH
CodeAstro Student Grading System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11116 HIGH
code-projects Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11115 HIGH
code-projects Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11114 MEDIUM
CodeAstro Online Leave Application 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11113 MEDIUM
CodeAstro Online Leave Application 1.0 - SQL Injection
CVSS 6.3
CVE-2025-11111 HIGH
Campcodes Advanced Online Voting Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11110 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11109 HIGH
Campcodes Computer Sales & Inventory System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11108 HIGH
Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11107 HIGH
Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11106 HIGH
Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11105 HIGH
Code-projects Simple Scheduling System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-11104 MEDIUM
CodeAstro Electricity Billing System 1.0 - SQL Injection
CVSS 6.3
Details
Vulnerabilities 19,572
Exploit Likelihood High