CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,580 vulnerabilities with CWE-89
CVE-2025-54788
HIGH
SuiteCRM < 7.14.7 - SQL Injection in InboundEmail Module
CVSS 8.8
CVE-2025-7036
HIGH
CleverReach WP <1.5.20 - SQL Injection
CVSS 7.5
CVE-2025-6986
MEDIUM
FileBird - WordPress Media Library Folders & File Manager <6.4.8 - ...
CVSS 6.5
CVE-2025-54865
HIGH
Tilesheets 5.0.1-5.0.3 - SQL Injection via Missing Backtick in Query
CVSS 7.3
CVE-2025-54119
CRITICAL
ADOdb < 5.22.10 - SQL Injection via metaColumns(), metaForeignKeys() or metaIndexes() Table Parameter
CVSS 10.0
CVE-2025-50341
CRITICAL
Axelor 5.2.4 - SQL Injection via _domain Parameter
CVSS 9.8
CVE-2025-8503
HIGH
Online Medicine Guide 1.0 - SQL Injection via mname Parameter in /adaddmed.php
CVSS 7.3
CVE-2025-8502
HIGH
Online Medicine Guide 1.0 - SQL Injection via /changepass.php ups Parameter
CVSS 7.3
CVE-2025-8500
MEDIUM
Human Resource Integrated System 1.0 - SQL Injection via /insert-and-view/action.php Content Parameter
CVSS 6.3
CVE-2025-8499
HIGH
Online Medicine Guide 1.0 - SQL Injection via Search Parameter in cusfindambulence2.php
CVSS 7.3
CVE-2025-8498
HIGH
Online Medicine Guide 1.0 - SQL Injection via uname Parameter in cart/index.php
CVSS 7.3
CVE-2025-8497
HIGH
Online Medicine Guide 1.0 - SQL Injection via Search Parameter in cusfindphar2.php
CVSS 7.3
CVE-2025-8496
HIGH
projectworlds Online Admission System 1.0 - SQL Injection via /viewform.php ID Parameter
CVSS 7.3
CVE-2025-8495
HIGH
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in edit_admin_query.php
CVSS 7.3
CVE-2025-8494
HIGH
Intern Membership Management System 1.0 - SQL Injection via /admin/delete_student.php ID Parameter
CVSS 7.3
CVE-2025-8493
HIGH
Intern Membership Management System 1.0 - SQL Injection via /admin/edit_student_query.php ID Parameter
CVSS 7.3
CVE-2025-8471
HIGH
projectworlds Online Admission System 1.0 - SQL Injection via /adminlogin.php a_id Parameter
CVSS 7.3
CVE-2025-8470
HIGH
SourceCodester Online Hotel Reservation System 1.0 - SQL Injection via ID Parameter in deleteroom.php
CVSS 7.3
CVE-2025-8469
HIGH
SourceCodester Online Hotel Reservation System 1.0 - SQL Injection via /admin/deletegallery.php ID Parameter
CVSS 7.3
CVE-2025-8468
HIGH
Wazifa System 1.0 - SQL Injection via Reset Controller Email Parameter
CVSS 7.3
CVE-2025-8467
HIGH
Wazifa System 1.0 - SQL Injection via Username Parameter in regcontrol.php
CVSS 7.3
CVE-2025-8466
HIGH
Online Farm System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-54790
MEDIUM
humhub/files < 0.16.10 - SQL Injection
CVSS 6.5
CVE-2025-50868
MEDIUM
CloudClassroom-PHP-Project 1.0 - SQL Injection
CVSS 6.5
CVE-2025-52390
CRITICAL
Saurus CMS Community Edition - SQL Injection
CVSS 9.1
Details
Vulnerabilities
19,580
Exploit Likelihood
High