CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,581 vulnerabilities with CWE-89
CVE-2025-7801 HIGH
BossSoft CRM 6.0 - SQL Injection via cstid Parameter in HNDCBas_customPrmSearchDtl.jsp
CVSS 7.3
CVE-2025-7798 MEDIUM
Beijing Shenzhou Shihan Technology Multimedia Integrated Business D...
CVSS 6.3
CVE-2025-50585 HIGH
daycloud studentmanage v1.0 - SQL Injection via /admin/adminStudentUrl
CVSS 8.8
CVE-2025-54079 HIGH
WeGIA < 3.4.6 - Authenticated SQL Injection via idatendido Parameter
CVSS 8.8
CVE-2025-49485 HIGH
Balbooa Forms <2.3.1.1 - SQL Injection
CVE-2025-49484 HIGH
JS Jobs component for Joomla 1.0.0-1.4.1 - Authenticated SQL Injection via 'cvid' Parameter
CVE-2025-26855 CRITICAL
Articles Calendar extension <1.0.1.0007 - SQL Injection
CVSS 9.8
CVE-2025-26854 CRITICAL
Articles Good Search <1.2.4.0011 - SQL Injection
CVSS 9.8
CVE-2025-6717 MEDIUM
B1.lt plugin <2.2.56 - SQL Injection
CVSS 6.5
CVE-2025-7638 MEDIUM
Forminator Forms - Contact Form, Payment Form & Custom Form Builder...
CVSS 4.9
CVE-2025-7765 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7764 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7757 HIGH
PHPGurukul Land Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7754 MEDIUM
Patient Record Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-7753 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7752 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7751 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6230 MEDIUM
Lenovo Vantage < 10.2501.20.0 and Commercial Vantage < 20.2506.39.0 - SQL Injection
CVSS 5.3
CVE-2025-7750 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-50240 CRITICAL
nbcio-boot 1.0.3 - SQL Injection via userIds Parameter
CVSS 9.8
CVE-2025-7749 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-25257 CRITICAL KEV
Fortinet FortiWeb - SQL Injection
CVSS 9.8
CVE-2025-54062 HIGH
WeGIA < 3.4.6 - SQL Injection via id_dependente Parameter
CVSS 8.8
CVE-2025-54061 HIGH
WeGIA < 3.4.6 - SQL Injection via idatendido_familiares Parameter
CVSS 8.8
CVE-2025-54060 HIGH
WeGIA < 3.4.6 - SQL Injection via idatendido_familiares Parameter
CVSS 8.8
Details
Vulnerabilities 19,581
Exploit Likelihood High