CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,599 vulnerabilities with CWE-89
CVE-2025-7522 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7521 HIGH
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 7.3
CVE-2025-7520 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7517 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7516 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7515 HIGH
code-projects Online Appointment Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7514 HIGH
code-projects Modern Bag 1.0 - SQL Injection via /admin/contact-list.php idStatus Parameter
CVSS 7.3
CVE-2025-7513 HIGH
code-projects Modern Bag 1.0 - SQL Injection via /admin/slideupdate.php idSlide Parameter
CVSS 7.3
CVE-2025-7512 HIGH
code-projects Modern Bag 1.0 - SQL Injection via Contact Name Parameter
CVSS 7.3
CVE-2025-7511 MEDIUM
code-projects Chat System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-7510 HIGH
code-projects Modern Bag 1.0 - SQL Injection via namepro Parameter
CVSS 7.3
CVE-2025-7509 HIGH
code-projects Modern Bag 1.0 - SQL Injection via idSlide Parameter
CVSS 7.3
CVE-2025-7508 HIGH
code-projects Modern Bag 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7492 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7491 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7490 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7489 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7484 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7483 HIGH
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 7.3
CVE-2025-7482 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7481 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7480 HIGH
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 7.3
CVE-2025-7479 MEDIUM
PHPGurukul Vehicle Parking Management System 1.13 - SQL Injection
CVSS 6.3
CVE-2025-7478 HIGH
code-projects Modern Bag 1.0 - SQL Injection via /admin/category-list.php idCate Parameter
CVSS 7.3
CVE-2025-7476 HIGH
Simple Car Rental System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 19,599
Exploit Likelihood High