CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,572 vulnerabilities with CWE-89
CVE-2025-9692
HIGH
Campcodes Online Shopping System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9691
HIGH
Campcodes Online Shopping System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9690
MEDIUM
SourceCodester Advanced School Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9689
MEDIUM
SourceCodester Advanced School Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-0165
HIGH
IBM watsonx Orchestrate Cartridge - SQL Injection
CVSS 7.6
CVE-2025-9686
MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9685
MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9684
MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9679
HIGH
itsourcecode Student Information System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-54946
CRITICAL
SUNNET Corporate Training Management System < 10.11 - SQL Injection
CVSS 9.8
CVE-2025-9678
HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9669
HIGH
Jinher OA 1.0 - SQL Injection via GetTreeDate.aspx ID Parameter
CVSS 7.3
CVE-2025-9667
MEDIUM
Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9666
MEDIUM
Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9665
MEDIUM
Code-projects Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-44033
CRITICAL
aaluoxiang oa_system 1.1 - SQL Injection via AddressMapper allDirector Method
CVSS 9.8
CVE-2025-29894
HIGH
Qsync Central <4.5.0.7 - SQL Injection
CVSS 8.8
CVE-2025-29893
HIGH
Qsync Central <4.5.0.7 - SQL Injection
CVSS 8.8
CVE-2025-9664
MEDIUM
Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9663
MEDIUM
Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9662
HIGH
Simple Grading System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9660
HIGH
SourceCodester Bakeshop Online Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9651
MEDIUM
shafhasan chatbox <156a39cde62f78532c3265a70eda12c70907e56f - SQL I...
CVSS 6.3
CVE-2025-9645
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9644
HIGH
iSourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities
19,572
Exploit Likelihood
High