CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,572 vulnerabilities with CWE-89
CVE-2025-10785
HIGH
Campcodes Grocery Sales and Inventory System 1.0 - SQL Injection via /manage_user.php ID Parameter
CVSS 7.3
CVE-2025-10784
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via /admin/edit_subject.php subject_code Parameter
CVSS 7.3
CVE-2025-10783
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via subject_code Parameter
CVSS 7.3
CVE-2025-10782
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via class_name Parameter
CVSS 7.3
CVE-2025-10781
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via class_name Parameter
CVSS 7.3
CVE-2025-10780
MEDIUM
CodeAstro Simple Pharmacy Management 1.0 - SQL Injection via bar_code Parameter in view.php
CVSS 6.3
CVE-2025-10762
MEDIUM
kuaifan DooTask <1.2.49 - SQL Injection
CVSS 6.3
CVE-2025-10002
MEDIUM
ClickWhale - Link Manager - SQL Injection
CVSS 4.9
CVE-2025-10652
MEDIUM
Robcore Netatmo <1.7 - SQL Injection
CVSS 6.5
CVE-2025-59431
CRITICAL
MapServer < 8.4.1 - SQL Injection via XML Filter Query PropertyName
CVSS 9.8
CVE-2025-10712
HIGH
07FLYCMS, 07FLY-CMS & 07FlyCRM <20250831 - SQL Injection
CVSS 7.3
CVE-2025-10688
HIGH
Pet Grooming Management Software 1.0 - SQL Injection via inv_no/insta_amt Parameter
CVSS 7.3
CVE-2025-10687
HIGH
SourceCodester Responsive E-Learning System 1.0 - SQL Injection via Username Parameter in add_teacher.php
CVSS 7.3
CVE-2025-10673
HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via classId Parameter
CVSS 7.3
CVE-2025-10670
HIGH
E-Logbook with Health Monitoring System for COVID-19 1.0 - SQL Injection via Profile ID Parameter
CVSS 7.3
CVE-2025-10668
HIGH
Online Discussion Forum 1.0 - SQL Injection via ID Parameter in Compose Message Admin
CVSS 7.3
CVE-2025-10667
HIGH
itsourcecode Online Discussion Forum 1.0 - SQL Injection via /members/compose_msg.php ID Parameter
CVSS 7.3
CVE-2025-40677
HIGH
Summar Software's Portal del Empleado - SQL Injection
CVE-2025-10665
MEDIUM
kidaze CourseSelectionSystem < 2017-06-18 - SQL Injection via csem Argument
CVSS 6.3
CVE-2025-10664
HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via /create-ticket.php Subject Parameter
CVSS 7.3
CVE-2025-10663
HIGH
PHPGurukul Online Course Registration 3.1 - SQL Injection via cgpa Parameter
CVSS 7.3
CVE-2025-10662
MEDIUM
SeaCMS <= 13.3 - SQL Injection via /admin_members.php ID Parameter
CVSS 4.7
CVE-2025-10627
MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via /admin/delete_user.php ID Parameter
CVSS 6.3
CVE-2025-10626
MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via /admin/update_s3.php Credits Parameter
CVSS 6.3
CVE-2025-10625
MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via Phone Parameter
CVSS 6.3
Details
Vulnerabilities
19,572
Exploit Likelihood
High