CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,576 vulnerabilities with CWE-89
CVE-2025-56216
HIGH
phpgurukul Hospital Management System 4.0 - SQL Injection via about-us.php pagetitle Parameter
CVSS 8.5
CVE-2025-56215
MEDIUM
phpgurukul Hospital Management System 4.0 - SQL Injection via contact.php pagetitle Parameter
CVSS 6.5
CVE-2025-56214
CRITICAL
phpgurukul Hospital Management System 4.0 - SQL Injection via Username Parameter
CVSS 9.8
CVE-2025-56212
CRITICAL
phpgurukul Hospital Management System 4.0 - SQL Injection via add-doctor.php docname Parameter
CVSS 9.8
CVE-2025-9399
MEDIUM
YiFang CMS <= 2.0.5 - SQL Injection via new_url Parameter in L_tool.php
CVSS 6.3
CVE-2025-9391
MEDIUM
Bjskzy Zhiyou ERP <11.0 - SQL Injection
CVSS 6.3
CVE-2025-6791
HIGH
Centreon Web 23.10.0-23.10.25 - SQL Injection in Monitoring Event Logs Page
CVSS 8.8
CVE-2025-51092
CRITICAL
LogIn-SignUp - SQL Injection via Unsafe Query Construction in DataBase.php
CVSS 9.8
CVE-2025-4650
HIGH
Centreon Web 23.10.0-23.10.25 - Authenticated SQL Injection via Meta Service Indicator Page
CVSS 7.2
CVE-2025-52085
HIGH
Yoosee 6.32.4 - Authenticated SQL Injection via Backend API Endpoint
CVSS 8.8
CVE-2025-51825
MEDIUM
JeecgBoot 3.4.3-3.8.0 - SQL Injection via Online CGReport Head ParseSql Endpoint
CVSS 6.5
CVE-2025-9255
HIGH
WebITR < 2.1.0.33 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2025-9311
HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-57761
HIGH
WeGIA < 3.4.10 - SQL Injection via id_funcionario Parameter
CVSS 8.8
CVE-2025-9307
HIGH
PHPGurukul Online Course Registration <3.1 - SQL Injection
CVSS 7.3
CVE-2025-9305
HIGH
SourceCodester Online Bank Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9304
HIGH
SourceCodester Online Bank Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-50860
MEDIUM
Easy Hosting Control Panel 20.04.1.b - SQL Injection
CVSS 5.4
CVE-2025-9302
HIGH
PHPGurukul User Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9238
HIGH
Swatadru Exam-Seating-Arrangement - SQL Injection in /student.php
CVSS 7.3
CVE-2025-9236
MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-55444
CRITICAL
Online Artwork & Fine Arts MCA Project 1.0 - SQL Injection
CVSS 9.8
CVE-2025-55732
HIGH
Frappe <15.74.2,14.96.15 - SQL Injection
CVSS 7.5
CVE-2025-55731
HIGH
Frappe <15.74.2, <14.96.15 - Info Disclosure
CVSS 8.8
CVE-2025-54726
CRITICAL
Miguel Useche JS Archive List - SQL Injection
CVSS 9.3
Details
Vulnerabilities
19,576
Exploit Likelihood
High