CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,572 vulnerabilities with CWE-89
CVE-2025-10118
HIGH
E-Logbook with Health Monitoring System for COVID-19 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-10115
HIGH
SiempreCMS <= 1.3.6 - SQL Injection via user_search_ajax.php name/userName Parameter
CVSS 7.3
CVE-2025-10114
HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via Name Parameter in Profile
CVSS 7.3
CVE-2025-10113
HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via ID Parameter in Room Module
CVSS 7.3
CVE-2025-10112
HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via Department ID Parameter
CVSS 7.3
CVE-2025-58454
HIGH
WeGIA < 3.4.11 - Authenticated SQL Injection via id_memorando Parameter
CVSS 8.2
CVE-2025-58453
HIGH
WeGIA < 3.4.11 - Authenticated SQL Injection via id_anexo Parameter
CVSS 8.2
CVE-2025-10111
HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via ID Parameter in Instructor Module
CVSS 7.3
CVE-2025-10110
MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Search Endpoint
CVSS 6.3
CVE-2025-10109
HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection via ID Parameter in delete_payment Action
CVSS 7.3
CVE-2025-58450
CRITICAL
prest < 2.0.0-rc3 - SQL Injection
CVE-2025-10108
HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-10106
MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Search Keyword Parameter
CVSS 6.3
CVE-2025-10105
MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Article Search Keyword Parameter
CVSS 6.3
CVE-2025-10104
HIGH
Online Event Judging System 1.0 - SQL Injection via txtsearch Parameter in review_search.php
CVSS 7.3
CVE-2025-55849
HIGH
WeiPHP < 5.0 - SQL Injection via SucaiController.class.php cancelTemplatee
CVSS 8.4
CVE-2025-10103
HIGH
Online Event Judging System 1.0 - SQL Injection via main_event Parameter
CVSS 7.3
CVE-2025-10102
HIGH
Online Event Judging System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-10100
HIGH
SourceCodester Simple Forum Discussion System 1.0 - SQL Injection via Username Parameter in admin_class.php
CVSS 7.3
CVE-2025-10098
MEDIUM
PHPGurukul User Management System 1.0 - SQL Injection via uid Parameter in edit-user-profile.php
CVSS 6.3
CVE-2025-56630
HIGH
FoxCMS < 1.2.5 - SQL Injection via Column Model Parameter
CVSS 7.3
CVE-2025-10090
HIGH
Jinher OA < 1.2 - SQL Injection via ID Parameter in GetTreeDate.aspx
CVSS 7.3
CVE-2025-10087
MEDIUM
Pet Grooming Management Software 1.0 - SQL Injection via product_id Parameter
CVSS 4.7
CVE-2025-10082
HIGH
SourceCodester Online Polling System 1.0 - SQL Injection via Email Parameter in manage-admins.php
CVSS 7.3
CVE-2025-10079
HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via Contact Parameter in get-quote.php
CVSS 7.3
Details
Vulnerabilities
19,572
Exploit Likelihood
High