CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-9643 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9441 MEDIUM
iATS Online Forms <1.2 - SQL Injection
CVSS 6.5
CVE-2025-9610 HIGH
Code-projects Online Event Judging System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-8858 HIGH
Clinic Image System - SQL Injection
CVSS 7.5
CVE-2025-9608 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9607 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9606 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9601 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9600 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9599 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9598 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9597 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9596 HIGH
itsourcecode Sports Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9594 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9593 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9592 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-57819 CRITICAL KEV
FreePBX 15.0-15.0.65 - Unauthenticated Authentication Bypass and Remote Code Execution
CVSS 9.8
CVE-2025-51972 MEDIUM
PuneethReddyHC Online Shopping System Advanced 1.0 - SQL Injection via Login Keyword Parameter
CVSS 6.5
CVE-2025-51971 MEDIUM
PuneethReddyHC Online Shopping System Advanced 1.0 - Reflected Cross-Site Scripting via register.php f_name Parameter
CVSS 5.4
CVE-2025-51969 MEDIUM
PuneethReddyHC Online Shopping System Advanced 1.0 - SQL Injection via product_id GET Parameter
CVSS 6.5
CVE-2025-51968 MEDIUM
PuneethReddyHC Online Shopping System Advanced 1.0 - SQL Injection via proId POST Parameter
CVSS 6.5
CVE-2025-54720 CRITICAL
SteelThemes Nest Addons <1.6.3 - SQL Injection
CVSS 9.3
CVE-2025-49404 HIGH
purethemes Listeo-Core <1.9.32 - SQL Injection
CVSS 8.5
CVE-2025-49402 HIGH
Houzez CRM <1.4.7 - Info Disclosure
CVSS 8.5
CVE-2025-39496 CRITICAL
WBW WooBeWoo Product Filter Pro <2.9.6 - SQL Injection
CVSS 9.3
Details
Vulnerabilities 19,572
Exploit Likelihood High