CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,572 vulnerabilities with CWE-89
CVE-2025-9643
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9441
MEDIUM
iATS Online Forms <1.2 - SQL Injection
CVSS 6.5
CVE-2025-9610
HIGH
Code-projects Online Event Judging System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-8858
HIGH
Clinic Image System - SQL Injection
CVSS 7.5
CVE-2025-9608
MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9607
MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9606
MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9601
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9600
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9599
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9598
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9597
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9596
HIGH
itsourcecode Sports Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9594
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9593
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9592
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-57819
CRITICAL
KEV
FreePBX 15.0-15.0.65 - Unauthenticated Authentication Bypass and Remote Code Execution
CVSS 9.8
CVE-2025-51972
MEDIUM
PuneethReddyHC Online Shopping System Advanced 1.0 - SQL Injection via Login Keyword Parameter
CVSS 6.5
CVE-2025-51971
MEDIUM
PuneethReddyHC Online Shopping System Advanced 1.0 - Reflected Cross-Site Scripting via register.php f_name Parameter
CVSS 5.4
CVE-2025-51969
MEDIUM
PuneethReddyHC Online Shopping System Advanced 1.0 - SQL Injection via product_id GET Parameter
CVSS 6.5
CVE-2025-51968
MEDIUM
PuneethReddyHC Online Shopping System Advanced 1.0 - SQL Injection via proId POST Parameter
CVSS 6.5
CVE-2025-54720
CRITICAL
SteelThemes Nest Addons <1.6.3 - SQL Injection
CVSS 9.3
CVE-2025-49404
HIGH
purethemes Listeo-Core <1.9.32 - SQL Injection
CVSS 8.5
CVE-2025-49402
HIGH
Houzez CRM <1.4.7 - Info Disclosure
CVSS 8.5
CVE-2025-39496
CRITICAL
WBW WooBeWoo Product Filter Pro <2.9.6 - SQL Injection
CVSS 9.3
Details
Vulnerabilities
19,572
Exploit Likelihood
High