CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,576 vulnerabilities with CWE-89
CVE-2025-8972 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via Email Parameter in Admin Login Page
CVSS 7.3
CVE-2025-8971 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via val-username Parameter
CVSS 7.3
CVE-2025-8970 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via Booking ID Parameter
CVSS 7.3
CVE-2025-8969 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via /admin/approve_user.php ID Parameter
CVSS 7.3
CVE-2025-8968 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via /admin/disapprove_user.php ID Parameter
CVSS 7.3
CVE-2025-8967 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via pname Parameter
CVSS 7.3
CVE-2025-8966 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via tax.php tname Parameter
CVSS 7.3
CVE-2025-55674 MEDIUM
Apache Superset <5.0.0 - Info Disclosure
CVSS 6.5
CVE-2025-8960 HIGH
Campcodes Online Flight Booking Management System 1.0 - SQL Injection via /admin/save_airlines.php ID Parameter
CVSS 7.3
CVE-2025-8957 HIGH
Campcodes Online Flight Booking Management System 1.0 - SQL Injection via flights.php departure_airport_id Parameter
CVSS 7.3
CVE-2025-54707 CRITICAL
RealMag777 MDTF <1.3.3.7 - SQL Injection
CVSS 9.3
CVE-2025-54678 CRITICAL
hassantafreshi Easy Form Builder <3.8.15 - SQL Injection
CVSS 9.3
CVE-2025-54669 CRITICAL
MapSVG < 8.7.4 - SQL Injection
CVSS 9.3
CVE-2025-52823 HIGH
ovatheme Cube Portfolio <1.16.8 - SQL Injection
CVSS 8.5
CVE-2025-52820 HIGH
WooCommerce POS <1.4 - SQL Injection
CVSS 8.5
CVE-2025-52720 CRITICAL
Highwarden Super Store Finder <7.5 - SQL Injection
CVSS 9.3
CVE-2025-49267 HIGH
Shabti Kaplan Frontend Admin <3.28.3 - SQL Injection
CVSS 8.5
CVE-2025-49059 CRITICAL
CleverReach WP <1.5.20 - SQL Injection
CVSS 9.3
CVE-2025-49033 HIGH
Metagauss ProfileGrid <5.9.5.3 - SQL Injection
CVSS 8.5
CVE-2025-39510 HIGH
ValvePress Pinterest Automatic Pin - SQL Injection
CVSS 8.5
CVE-2025-30998 HIGH
Rico Macchi WP Links Page <4.9.6 - SQL Injection
CVSS 8.5
CVE-2025-8955 HIGH
PHPGurukul Hospital Management System 4.0 - SQL Injection via docfees Parameter
CVSS 7.3
CVE-2025-8954 HIGH
PHPGurukul Hospital Management System 4.0 - SQL Injection via doctorspecilization Parameter
CVSS 7.3
CVE-2025-8953 HIGH
COVID 19 Testing Management System 1.0 - SQL Injection via Employee ID Parameter
CVSS 7.3
CVE-2025-8952 HIGH
Campcodes Online Flight Booking Management System 1.0 - SQL Injection via Login Username Parameter
CVSS 7.3
Details
Vulnerabilities 19,576
Exploit Likelihood High