CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,576 vulnerabilities with CWE-89
CVE-2025-8972
HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via Email Parameter in Admin Login Page
CVSS 7.3
CVE-2025-8971
HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via val-username Parameter
CVSS 7.3
CVE-2025-8970
HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via Booking ID Parameter
CVSS 7.3
CVE-2025-8969
HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via /admin/approve_user.php ID Parameter
CVSS 7.3
CVE-2025-8968
HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via /admin/disapprove_user.php ID Parameter
CVSS 7.3
CVE-2025-8967
HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via pname Parameter
CVSS 7.3
CVE-2025-8966
HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via tax.php tname Parameter
CVSS 7.3
CVE-2025-55674
MEDIUM
Apache Superset <5.0.0 - Info Disclosure
CVSS 6.5
CVE-2025-8960
HIGH
Campcodes Online Flight Booking Management System 1.0 - SQL Injection via /admin/save_airlines.php ID Parameter
CVSS 7.3
CVE-2025-8957
HIGH
Campcodes Online Flight Booking Management System 1.0 - SQL Injection via flights.php departure_airport_id Parameter
CVSS 7.3
CVE-2025-54707
CRITICAL
RealMag777 MDTF <1.3.3.7 - SQL Injection
CVSS 9.3
CVE-2025-54678
CRITICAL
hassantafreshi Easy Form Builder <3.8.15 - SQL Injection
CVSS 9.3
CVE-2025-54669
CRITICAL
MapSVG < 8.7.4 - SQL Injection
CVSS 9.3
CVE-2025-52823
HIGH
ovatheme Cube Portfolio <1.16.8 - SQL Injection
CVSS 8.5
CVE-2025-52820
HIGH
WooCommerce POS <1.4 - SQL Injection
CVSS 8.5
CVE-2025-52720
CRITICAL
Highwarden Super Store Finder <7.5 - SQL Injection
CVSS 9.3
CVE-2025-49267
HIGH
Shabti Kaplan Frontend Admin <3.28.3 - SQL Injection
CVSS 8.5
CVE-2025-49059
CRITICAL
CleverReach WP <1.5.20 - SQL Injection
CVSS 9.3
CVE-2025-49033
HIGH
Metagauss ProfileGrid <5.9.5.3 - SQL Injection
CVSS 8.5
CVE-2025-39510
HIGH
ValvePress Pinterest Automatic Pin - SQL Injection
CVSS 8.5
CVE-2025-30998
HIGH
Rico Macchi WP Links Page <4.9.6 - SQL Injection
CVSS 8.5
CVE-2025-8955
HIGH
PHPGurukul Hospital Management System 4.0 - SQL Injection via docfees Parameter
CVSS 7.3
CVE-2025-8954
HIGH
PHPGurukul Hospital Management System 4.0 - SQL Injection via doctorspecilization Parameter
CVSS 7.3
CVE-2025-8953
HIGH
COVID 19 Testing Management System 1.0 - SQL Injection via Employee ID Parameter
CVSS 7.3
CVE-2025-8952
HIGH
Campcodes Online Flight Booking Management System 1.0 - SQL Injection via Login Username Parameter
CVSS 7.3
Details
Vulnerabilities
19,576
Exploit Likelihood
High