CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-8977 MEDIUM
Simple Download Monitor <3.9.33 - SQL Injection
CVSS 6.5
CVE-2025-34162 CRITICAL
Bian Que Feijiu Intelligent Emergency - SQL Injection
CVE-2025-51667 HIGH
simple-admin-core 1.2.0-1.6.7 - SQL Injection via /sys-api/role/update Interface
CVSS 7.0
CVE-2025-50979 HIGH
NodeBB v4.3.0 - Unauthenticated SQL Injection via Search-Categories API Endpoint
CVSS 8.6
CVE-2025-50984 MEDIUM
diskover-web v2.3.0 CE - SQL Injection
CVSS 5.3
CVE-2025-50983 HIGH
readarr 0.4.15.2787 - SQL Injection
CVSS 8.3
CVE-2025-50972 CRITICAL
AbanteCart 1.4.2 - Unauthenticated SQL Injection via tmpl_id Parameter
CVSS 9.8
CVE-2025-9532 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-9531 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-30061 MEDIUM
OpenReportWindow.pl - SQL Injection
CVE-2025-30060 MEDIUM
ReturnUserUnitsXML.pl - SQL Injection
CVE-2025-30059 MEDIUM
PrepareCDExportJSON.pl - SQL Injection
CVE-2025-30058 MEDIUM
CGM CLININET < 2024.MS4 - SQL Injection via PatientService.pl pesel Parameter
CVE-2025-9511 HIGH
Isourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9510 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9509 HIGH
iSourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9508 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9507 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9506 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9505 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9504 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9503 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9502 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9492 HIGH
Campcodes Online Water Billing System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9473 HIGH
SourceCodester Online Bank Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,572
Exploit Likelihood High