CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,576 vulnerabilities with CWE-89
CVE-2025-56216 HIGH
phpgurukul Hospital Management System 4.0 - SQL Injection via about-us.php pagetitle Parameter
CVSS 8.5
CVE-2025-56215 MEDIUM
phpgurukul Hospital Management System 4.0 - SQL Injection via contact.php pagetitle Parameter
CVSS 6.5
CVE-2025-56214 CRITICAL
phpgurukul Hospital Management System 4.0 - SQL Injection via Username Parameter
CVSS 9.8
CVE-2025-56212 CRITICAL
phpgurukul Hospital Management System 4.0 - SQL Injection via add-doctor.php docname Parameter
CVSS 9.8
CVE-2025-9399 MEDIUM
YiFang CMS <= 2.0.5 - SQL Injection via new_url Parameter in L_tool.php
CVSS 6.3
CVE-2025-9391 MEDIUM
Bjskzy Zhiyou ERP <11.0 - SQL Injection
CVSS 6.3
CVE-2025-6791 HIGH
Centreon Web 23.10.0-23.10.25 - SQL Injection in Monitoring Event Logs Page
CVSS 8.8
CVE-2025-51092 CRITICAL
LogIn-SignUp - SQL Injection via Unsafe Query Construction in DataBase.php
CVSS 9.8
CVE-2025-4650 HIGH
Centreon Web 23.10.0-23.10.25 - Authenticated SQL Injection via Meta Service Indicator Page
CVSS 7.2
CVE-2025-52085 HIGH
Yoosee 6.32.4 - Authenticated SQL Injection via Backend API Endpoint
CVSS 8.8
CVE-2025-51825 MEDIUM
JeecgBoot 3.4.3-3.8.0 - SQL Injection via Online CGReport Head ParseSql Endpoint
CVSS 6.5
CVE-2025-9255 HIGH
WebITR < 2.1.0.33 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2025-9311 HIGH
itsourcecode Apartment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-57761 HIGH
WeGIA < 3.4.10 - SQL Injection via id_funcionario Parameter
CVSS 8.8
CVE-2025-9307 HIGH
PHPGurukul Online Course Registration <3.1 - SQL Injection
CVSS 7.3
CVE-2025-9305 HIGH
SourceCodester Online Bank Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9304 HIGH
SourceCodester Online Bank Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-50860 MEDIUM
Easy Hosting Control Panel 20.04.1.b - SQL Injection
CVSS 5.4
CVE-2025-9302 HIGH
PHPGurukul User Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-9238 HIGH
Swatadru Exam-Seating-Arrangement - SQL Injection in /student.php
CVSS 7.3
CVE-2025-9236 MEDIUM
Portabilis i-Educar <2.10 - SQL Injection
CVSS 6.3
CVE-2025-55444 CRITICAL
Online Artwork & Fine Arts MCA Project 1.0 - SQL Injection
CVSS 9.8
CVE-2025-55732 HIGH
Frappe <15.74.2,14.96.15 - SQL Injection
CVSS 7.5
CVE-2025-55731 HIGH
Frappe <15.74.2, <14.96.15 - Info Disclosure
CVSS 8.8
CVE-2025-54726 CRITICAL
Miguel Useche JS Archive List - SQL Injection
CVSS 9.3
Details
Vulnerabilities 19,576
Exploit Likelihood High