CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,572 vulnerabilities with CWE-89
CVE-2025-9472 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9471 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9470 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9469 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9468 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9172 HIGH
Vibes plugin <2.2.0 - SQL Injection
CVSS 7.5
CVE-2025-9444 HIGH
1000projects Online Student Project Report Submission And Evaluation System - Injection
CVSS 7.3
CVE-2025-9426 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via subcatid Parameter in package.php
CVSS 7.3
CVE-2025-9425 HIGH
iSourcecode Online Tour <1.0 - SQL Injection
CVSS 7.3
CVE-2025-9423 HIGH
Campcodes Online Water Billing System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9421 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9420 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9419 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9418 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9417 MEDIUM
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-9413 MEDIUM
lostvip ruoyi-go < 2.1 - SQL Injection via SelectListByPage orderByColumn/isAsc Parameters
CVSS 6.3
CVE-2025-9412 MEDIUM
lostvip-com ruoyi-go <2.1 - SQL Injection
CVSS 6.3
CVE-2025-50383 HIGH
Easy!Appointments v1.5.1 - SQL Injection
CVSS 8.1
CVE-2025-9411 MEDIUM
lostvip ruoyi-go < 2.1 - SQL Injection via isAsc Argument in SelectPageList
CVSS 6.3
CVE-2025-9410 MEDIUM
ruoyi-go < 2.1 - SQL Injection via SelectListByPage Function
CVSS 6.3
CVE-2025-55575 CRITICAL
SMM Panel 3.1 - SQL Injection via action=service_detail Parameter
CVSS 9.8
CVE-2025-56216 HIGH
phpgurukul Hospital Management System 4.0 - SQL Injection via about-us.php pagetitle Parameter
CVSS 8.5
CVE-2025-56215 MEDIUM
phpgurukul Hospital Management System 4.0 - SQL Injection via contact.php pagetitle Parameter
CVSS 6.5
CVE-2025-56214 CRITICAL
phpgurukul Hospital Management System 4.0 - SQL Injection via Username Parameter
CVSS 9.8
CVE-2025-56212 CRITICAL
phpgurukul Hospital Management System 4.0 - SQL Injection via add-doctor.php docname Parameter
CVSS 9.8
Details
Vulnerabilities 19,572
Exploit Likelihood High