CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-10118 HIGH
E-Logbook with Health Monitoring System for COVID-19 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-10115 HIGH
SiempreCMS <= 1.3.6 - SQL Injection via user_search_ajax.php name/userName Parameter
CVSS 7.3
CVE-2025-10114 HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via Name Parameter in Profile
CVSS 7.3
CVE-2025-10113 HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via ID Parameter in Room Module
CVSS 7.3
CVE-2025-10112 HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via Department ID Parameter
CVSS 7.3
CVE-2025-58454 HIGH
WeGIA < 3.4.11 - Authenticated SQL Injection via id_memorando Parameter
CVSS 8.2
CVE-2025-58453 HIGH
WeGIA < 3.4.11 - Authenticated SQL Injection via id_anexo Parameter
CVSS 8.2
CVE-2025-10111 HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via ID Parameter in Instructor Module
CVSS 7.3
CVE-2025-10110 MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Search Endpoint
CVSS 6.3
CVE-2025-10109 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection via ID Parameter in delete_payment Action
CVSS 7.3
CVE-2025-58450 CRITICAL
prest < 2.0.0-rc3 - SQL Injection
CVE-2025-10108 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-10106 MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Search Keyword Parameter
CVSS 6.3
CVE-2025-10105 MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Article Search Keyword Parameter
CVSS 6.3
CVE-2025-10104 HIGH
Online Event Judging System 1.0 - SQL Injection via txtsearch Parameter in review_search.php
CVSS 7.3
CVE-2025-55849 HIGH
WeiPHP < 5.0 - SQL Injection via SucaiController.class.php cancelTemplatee
CVSS 8.4
CVE-2025-10103 HIGH
Online Event Judging System 1.0 - SQL Injection via main_event Parameter
CVSS 7.3
CVE-2025-10102 HIGH
Online Event Judging System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-10100 HIGH
SourceCodester Simple Forum Discussion System 1.0 - SQL Injection via Username Parameter in admin_class.php
CVSS 7.3
CVE-2025-10098 MEDIUM
PHPGurukul User Management System 1.0 - SQL Injection via uid Parameter in edit-user-profile.php
CVSS 6.3
CVE-2025-56630 HIGH
FoxCMS < 1.2.5 - SQL Injection via Column Model Parameter
CVSS 7.3
CVE-2025-10090 HIGH
Jinher OA < 1.2 - SQL Injection via ID Parameter in GetTreeDate.aspx
CVSS 7.3
CVE-2025-10087 MEDIUM
Pet Grooming Management Software 1.0 - SQL Injection via product_id Parameter
CVSS 4.7
CVE-2025-10082 HIGH
SourceCodester Online Polling System 1.0 - SQL Injection via Email Parameter in manage-admins.php
CVSS 7.3
CVE-2025-10079 HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via Contact Parameter in get-quote.php
CVSS 7.3
Details
Vulnerabilities 19,572
Exploit Likelihood High