CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,581 vulnerabilities with CWE-89
CVE-2025-7929 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7928 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7927 MEDIUM
PHPGurukul Online Banquet Booking System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-7624 CRITICAL
Sophos Firewall <21.0 - SQL Injection
CVSS 9.8
CVE-2025-41678 MEDIUM
mbnet.mini_firmware < 2.3.3 - SQL Injection via POST Request
CVSS 6.5
CVE-2025-7343 CRITICAL
Digiwin SFT < 3.7.12 - Unauthenticated SQL Injection
CVSS 9.8
CVE-2025-7918 CRITICAL
Simopro Technology WinMatrix3 Web package < 1.2.39.5 - Unauthenticated SQL Injection
CVSS 9.8
CVE-2025-7915 HIGH
Chanjet CRM 1.0 - SQL Injection via /mail/mailinactive.php
CVSS 7.3
CVE-2025-7905 MEDIUM
itsourcecode Insurance Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-7904 MEDIUM
itsourcecode Insurance Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-7894 MEDIUM
Onyx < 0.29.1 - SQL Injection via generate_simple_sql Function
CVSS 6.3
CVE-2025-7888 MEDIUM
TDuckCloud tduck-platform 5.1 - SQL Injection
CVSS 6.3
CVE-2025-7886 HIGH
pmTicket Project-Management-Software <2ef379da2075f4761a2c9029cf91d...
CVSS 7.3
CVE-2025-7873 MEDIUM
MetaCRM < 6.4.2 - SQL Injection via mcc_login.jsp workerid Parameter
CVSS 6.3
CVE-2025-7861 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7860 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7859 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7838 HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via /admin/manage_seat.php ID Parameter
CVSS 7.3
CVE-2025-7833 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7832 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7831 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7830 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7829 HIGH
Church Donation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-52924 MEDIUM
One Identity OneLogin <2025.2.0 - SQL Injection
CVSS 4.0
CVE-2025-7814 HIGH
Food Ordering Review System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,581
Exploit Likelihood High