CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-10785 HIGH
Campcodes Grocery Sales and Inventory System 1.0 - SQL Injection via /manage_user.php ID Parameter
CVSS 7.3
CVE-2025-10784 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via /admin/edit_subject.php subject_code Parameter
CVSS 7.3
CVE-2025-10783 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via subject_code Parameter
CVSS 7.3
CVE-2025-10782 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via class_name Parameter
CVSS 7.3
CVE-2025-10781 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via class_name Parameter
CVSS 7.3
CVE-2025-10780 MEDIUM
CodeAstro Simple Pharmacy Management 1.0 - SQL Injection via bar_code Parameter in view.php
CVSS 6.3
CVE-2025-10762 MEDIUM
kuaifan DooTask <1.2.49 - SQL Injection
CVSS 6.3
CVE-2025-10002 MEDIUM
ClickWhale - Link Manager - SQL Injection
CVSS 4.9
CVE-2025-10652 MEDIUM
Robcore Netatmo <1.7 - SQL Injection
CVSS 6.5
CVE-2025-59431 CRITICAL
MapServer < 8.4.1 - SQL Injection via XML Filter Query PropertyName
CVSS 9.8
CVE-2025-10712 HIGH
07FLYCMS, 07FLY-CMS & 07FlyCRM <20250831 - SQL Injection
CVSS 7.3
CVE-2025-10688 HIGH
Pet Grooming Management Software 1.0 - SQL Injection via inv_no/insta_amt Parameter
CVSS 7.3
CVE-2025-10687 HIGH
SourceCodester Responsive E-Learning System 1.0 - SQL Injection via Username Parameter in add_teacher.php
CVSS 7.3
CVE-2025-10673 HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via classId Parameter
CVSS 7.3
CVE-2025-10670 HIGH
E-Logbook with Health Monitoring System for COVID-19 1.0 - SQL Injection via Profile ID Parameter
CVSS 7.3
CVE-2025-10668 HIGH
Online Discussion Forum 1.0 - SQL Injection via ID Parameter in Compose Message Admin
CVSS 7.3
CVE-2025-10667 HIGH
itsourcecode Online Discussion Forum 1.0 - SQL Injection via /members/compose_msg.php ID Parameter
CVSS 7.3
CVE-2025-40677 HIGH
Summar Software's Portal del Empleado - SQL Injection
CVE-2025-10665 MEDIUM
kidaze CourseSelectionSystem < 2017-06-18 - SQL Injection via csem Argument
CVSS 6.3
CVE-2025-10664 HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via /create-ticket.php Subject Parameter
CVSS 7.3
CVE-2025-10663 HIGH
PHPGurukul Online Course Registration 3.1 - SQL Injection via cgpa Parameter
CVSS 7.3
CVE-2025-10662 MEDIUM
SeaCMS <= 13.3 - SQL Injection via /admin_members.php ID Parameter
CVSS 4.7
CVE-2025-10627 MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via /admin/delete_user.php ID Parameter
CVSS 6.3
CVE-2025-10626 MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via /admin/update_s3.php Credits Parameter
CVSS 6.3
CVE-2025-10625 MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via Phone Parameter
CVSS 6.3
Details
Vulnerabilities 19,572
Exploit Likelihood High