CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,591 vulnerabilities with CWE-89
CVE-2025-7560 MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection
CVSS 6.3
CVE-2025-7559 MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection
CVSS 6.3
CVE-2025-7558 MEDIUM
code-projects Voting System 1.0 - SQL Injection via /admin/positions_add.php Description Parameter
CVSS 6.3
CVE-2025-7557 MEDIUM
Code-projects Voting System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-7556 MEDIUM
code-projects Voting System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-7555 MEDIUM
code-projects Voting System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-1735 MEDIUM
PHP 8.1.0-8.1.32 - Denial of Service via PostgreSQL Escaping Function Error Handling
CVSS 5.9
CVE-2025-7543 MEDIUM
PHPGurukul User Registration & Login and User Management System 3.3 - SQL Injection via ID Parameter in manage-users.php
CVSS 6.3
CVE-2025-7542 HIGH
PHPGurukul User Registration & Login and User Management System 3.3 - SQL Injection via uid Parameter
CVSS 7.3
CVE-2025-7541 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7540 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7539 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7537 HIGH
Campcodes Sales & Inventory System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7536 HIGH
Campcodes Sales and Inventory System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7535 HIGH
Campcodes Sales and Inventory System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7534 HIGH
PHPGurukul Student Result Management System 2.0 - SQL Injection
CVSS 7.3
CVE-2025-7533 HIGH
Job Diary 1.0 - SQL Injection via job_id Parameter in view-details.php
CVSS 7.3
CVE-2025-7522 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7521 HIGH
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 7.3
CVE-2025-7520 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7517 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7516 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7515 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7514 HIGH
code-projects Modern Bag 1.0 - SQL Injection via /admin/contact-list.php idStatus Parameter
CVSS 7.3
CVE-2025-7513 HIGH
code-projects Modern Bag 1.0 - SQL Injection via /admin/slideupdate.php idSlide Parameter
CVSS 7.3
Details
Vulnerabilities 19,591
Exploit Likelihood High