CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,591 vulnerabilities with CWE-89
CVE-2025-24759 CRITICAL
CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirecto...
CVSS 9.3
CVE-2025-54043 HIGH
YayCommerce SMTP <1.9 - SQL Injection
CVSS 7.6
CVE-2025-54026 HIGH
QuanticaLabs GymBase Theme Classes <1.4 - SQL Injection
CVSS 8.5
CVE-2025-48301 HIGH
YayCommerce SMTP for SendGrid - YaySMTP <= 1.5 - SQL Injection
CVSS 7.6
CVE-2025-48299 HIGH
YayCommerce YayExtra <1.5.5 - SQL Injection
CVSS 7.6
CVE-2025-48161 HIGH
YayCommerce YaySMTP <= 1.3 - SQL Injection
CVSS 7.6
CVE-2025-40985 HIGH
SCATI Vision Web <7.2 - SQL Injection
CVE-2025-26186 HIGH
openSIS 9.1 - SQL Injection via Ajax.php id Parameter
CVSS 8.1
CVE-2025-34112 CRITICAL
Riverbed SteelCentral NetProfiler & NetExpress <10.8.7 - RCE
CVE-2025-53823 HIGH
WeGIA < 3.4.5 - SQL Injection via id_socio Parameter
CVSS 8.8
CVE-2025-53639 CRITICAL
MeterSphere <3.6.5-lts - SQL Injection
CVSS 9.8
CVE-2025-51660 MEDIUM
SemCms < 5.0 - SQL Injection via lgid Parameter at SEMCMS_Products.php
CVSS 5.4
CVE-2025-51659 MEDIUM
semcms < 5.0 - SQL Injection via ID Parameter at SEMCMS_Products.php
CVSS 5.4
CVE-2025-51658 MEDIUM
SemCms < 5.0 - SQL Injection via SEMCMS_InquiryView.php ID Parameter
CVSS 5.4
CVE-2025-51657 MEDIUM
SemCms < 5.0 - SQL Injection via lgid Parameter at SEMCMS_Link.php
CVSS 5.4
CVE-2025-51656 MEDIUM
SemCms < 5.0 - SQL Injection via ID Parameter at SEMCMS_Link.php
CVSS 5.4
CVE-2025-51655 MEDIUM
SemCms < 5.0 - SQL Injection via pid Parameter at SEMCMS_Quanxian.php
CVSS 5.4
CVE-2025-51654 MEDIUM
SemCms < 5.0 - SQL Injection via pid Parameter
CVSS 5.4
CVE-2025-51653 MEDIUM
SemCms < 5.0 - SQL Injection via SEMCMS_ct.php pid Parameter
CVSS 5.4
CVE-2025-51652 MEDIUM
SemCms < 5.0 - SQL Injection via pid Parameter
CVSS 5.4
CVE-2025-7612 HIGH
code-projects Mobile Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7611 HIGH
Wedding Reservation 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7610 HIGH
code-projects Electricity Billing System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7609 HIGH
Simple Shopping Cart 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7608 HIGH
Simple Shopping Cart 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,591
Exploit Likelihood High