CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,591 vulnerabilities with CWE-89
CVE-2025-7752 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7751 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6230 MEDIUM
Lenovo Vantage < 10.2501.20.0 and Commercial Vantage < 20.2506.39.0 - SQL Injection
CVSS 5.3
CVE-2025-7750 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-50240 CRITICAL
nbcio-boot 1.0.3 - SQL Injection via userIds Parameter
CVSS 9.8
CVE-2025-7749 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-25257 CRITICAL KEV
Fortinet FortiWeb - SQL Injection
CVSS 9.8
CVE-2025-54062 HIGH
WeGIA < 3.4.6 - SQL Injection via id_dependente Parameter
CVSS 8.8
CVE-2025-54061 HIGH
WeGIA < 3.4.6 - SQL Injection via idatendido_familiares Parameter
CVSS 8.8
CVE-2025-54060 HIGH
WeGIA < 3.4.6 - SQL Injection via idatendido_familiares Parameter
CVSS 8.8
CVE-2025-54058 HIGH
WeGIA < 3.4.6 - SQL Injection via idatendido_familiares Parameter
CVSS 8.8
CVE-2025-53946 HIGH
WeGIA < 3.4.5 - SQL Injection via id_funcionario Parameter
CVSS 8.8
CVE-2025-7735 HIGH
UNIMAX Hospital Information System < 2024.1.2.1 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2025-20272 MEDIUM
Cisco Prime Infrastructure/EPNM - SQL Injection
CVSS 4.3
CVE-2025-53937 CRITICAL
WeGIA < 3.4.5 - SQL Injection via controle/control.php cargo Parameter
CVSS 9.8
CVE-2025-37104 HIGH
HPE Telco Service Orchestrator - SQL Injection
CVSS 7.1
CVE-2025-52819 HIGH
Pakke Envíos <=1.0.2 - SQL Injection
CVSS 8.5
CVE-2025-52714 CRITICAL
shinetheme Traveler - SQL Injection
CVSS 9.3
CVE-2025-49876 HIGH
Metagauss ProfileGrid <5.9.5.2 - SQL Injection
CVSS 8.5
CVE-2025-49034 HIGH
FunnelKit Funnel Builder <3.10.2 - SQL Injection
CVSS 7.6
CVE-2025-47645 HIGH
ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices &...
CVSS 8.5
CVE-2025-32574 HIGH
Mojoomla WPGYM <65.0 - SQL Injection
CVSS 8.5
CVE-2025-30936 CRITICAL
Torod <= 2.1 - SQL Injection
CVSS 9.3
CVE-2025-28982 CRITICAL
ThimPress WP Pipes <= 1.4.3 - SQL Injection
CVSS 9.3
CVE-2025-28959 CRITICAL
Md Yeasin Ul Haider URL Shortener <3.0.7 - SQL Injection
CVSS 9.3
Details
Vulnerabilities 19,591
Exploit Likelihood High