CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-9692 HIGH
Campcodes Online Shopping System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9691 HIGH
Campcodes Online Shopping System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9690 MEDIUM
SourceCodester Advanced School Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9689 MEDIUM
SourceCodester Advanced School Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-0165 HIGH
IBM watsonx Orchestrate Cartridge - SQL Injection
CVSS 7.6
CVE-2025-9686 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9685 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9684 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9679 HIGH
itsourcecode Student Information System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-54946 CRITICAL
SUNNET Corporate Training Management System < 10.11 - SQL Injection
CVSS 9.8
CVE-2025-9678 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9669 HIGH
Jinher OA 1.0 - SQL Injection via GetTreeDate.aspx ID Parameter
CVSS 7.3
CVE-2025-9667 MEDIUM
Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9666 MEDIUM
Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9665 MEDIUM
Code-projects Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-44033 CRITICAL
aaluoxiang oa_system 1.1 - SQL Injection via AddressMapper allDirector Method
CVSS 9.8
CVE-2025-29894 HIGH
Qsync Central <4.5.0.7 - SQL Injection
CVSS 8.8
CVE-2025-29893 HIGH
Qsync Central <4.5.0.7 - SQL Injection
CVSS 8.8
CVE-2025-9664 MEDIUM
Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9663 MEDIUM
Simple Grading System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9662 HIGH
Simple Grading System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9660 HIGH
SourceCodester Bakeshop Online Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9651 MEDIUM
shafhasan chatbox <156a39cde62f78532c3265a70eda12c70907e56f - SQL I...
CVSS 6.3
CVE-2025-9645 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9644 HIGH
iSourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,572
Exploit Likelihood High