CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,580 vulnerabilities with CWE-89
CVE-2025-54788 HIGH
SuiteCRM < 7.14.7 - SQL Injection in InboundEmail Module
CVSS 8.8
CVE-2025-7036 HIGH
CleverReach WP <1.5.20 - SQL Injection
CVSS 7.5
CVE-2025-6986 MEDIUM
FileBird - WordPress Media Library Folders & File Manager <6.4.8 - ...
CVSS 6.5
CVE-2025-54865 HIGH
Tilesheets 5.0.1-5.0.3 - SQL Injection via Missing Backtick in Query
CVSS 7.3
CVE-2025-54119 CRITICAL
ADOdb < 5.22.10 - SQL Injection via metaColumns(), metaForeignKeys() or metaIndexes() Table Parameter
CVSS 10.0
CVE-2025-50341 CRITICAL
Axelor 5.2.4 - SQL Injection via _domain Parameter
CVSS 9.8
CVE-2025-8503 HIGH
Online Medicine Guide 1.0 - SQL Injection via mname Parameter in /adaddmed.php
CVSS 7.3
CVE-2025-8502 HIGH
Online Medicine Guide 1.0 - SQL Injection via /changepass.php ups Parameter
CVSS 7.3
CVE-2025-8500 MEDIUM
Human Resource Integrated System 1.0 - SQL Injection via /insert-and-view/action.php Content Parameter
CVSS 6.3
CVE-2025-8499 HIGH
Online Medicine Guide 1.0 - SQL Injection via Search Parameter in cusfindambulence2.php
CVSS 7.3
CVE-2025-8498 HIGH
Online Medicine Guide 1.0 - SQL Injection via uname Parameter in cart/index.php
CVSS 7.3
CVE-2025-8497 HIGH
Online Medicine Guide 1.0 - SQL Injection via Search Parameter in cusfindphar2.php
CVSS 7.3
CVE-2025-8496 HIGH
projectworlds Online Admission System 1.0 - SQL Injection via /viewform.php ID Parameter
CVSS 7.3
CVE-2025-8495 HIGH
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in edit_admin_query.php
CVSS 7.3
CVE-2025-8494 HIGH
Intern Membership Management System 1.0 - SQL Injection via /admin/delete_student.php ID Parameter
CVSS 7.3
CVE-2025-8493 HIGH
Intern Membership Management System 1.0 - SQL Injection via /admin/edit_student_query.php ID Parameter
CVSS 7.3
CVE-2025-8471 HIGH
projectworlds Online Admission System 1.0 - SQL Injection via /adminlogin.php a_id Parameter
CVSS 7.3
CVE-2025-8470 HIGH
SourceCodester Online Hotel Reservation System 1.0 - SQL Injection via ID Parameter in deleteroom.php
CVSS 7.3
CVE-2025-8469 HIGH
SourceCodester Online Hotel Reservation System 1.0 - SQL Injection via /admin/deletegallery.php ID Parameter
CVSS 7.3
CVE-2025-8468 HIGH
Wazifa System 1.0 - SQL Injection via Reset Controller Email Parameter
CVSS 7.3
CVE-2025-8467 HIGH
Wazifa System 1.0 - SQL Injection via Username Parameter in regcontrol.php
CVSS 7.3
CVE-2025-8466 HIGH
Online Farm System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-54790 MEDIUM
humhub/files < 0.16.10 - SQL Injection
CVSS 6.5
CVE-2025-50868 MEDIUM
CloudClassroom-PHP-Project 1.0 - SQL Injection
CVSS 6.5
CVE-2025-52390 CRITICAL
Saurus CMS Community Edition - SQL Injection
CVSS 9.1
Details
Vulnerabilities 19,580
Exploit Likelihood High