CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,599 vulnerabilities with CWE-89
CVE-2025-7475 HIGH
Simple Car Rental System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7474 HIGH
Job Diary 1.0 - SQL Injection via Search Parameter in /search.php
CVSS 7.3
CVE-2025-7471 HIGH
code-projects Modern Bag 1.0 - SQL Injection via /admin/login-back.php user-name Parameter
CVSS 7.3
CVE-2025-7469 HIGH
Campcodes Sales and Inventory System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7467 HIGH
code-projects Modern Bag 1.0 - SQL Injection via /product-detail.php ID Parameter
CVSS 7.3
CVE-2025-7466 HIGH
1000projects ABC Courier Management 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7461 HIGH
code-projects Modern Bag 1.0 - SQL Injection via proId Parameter in /action.php
CVSS 7.3
CVE-2025-7459 HIGH
code-projects Mobile Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7457 HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via ID Parameter in manage_movie.php
CVSS 7.3
CVE-2025-7456 HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via Reserve.php ID Parameter
CVSS 7.3
CVE-2025-7455 HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via /manage_reserve.php mid Parameter
CVSS 7.3
CVE-2025-7454 HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via /admin/manage_theater.php ID Parameter
CVSS 7.3
CVE-2025-7442 HIGH
WPGYM - Wordpress Gym Management System <67.8.0 - SQL Injection
CVSS 7.5
CVE-2025-7436 HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-53515 HIGH
Advantech iView - SQL Injection, RCE
CVSS 8.8
CVE-2025-53475 HIGH
Advantech iView - SQL Injection, RCE
CVSS 8.8
CVE-2025-52577 HIGH
Advantech iView < 5.7.05.7057 - SQLi & RCE via NetworkServlet.archiveTrapRange()
CVSS 8.8
CVE-2025-48891 HIGH
Advantech iView < 5.7.05.7057 - Authenticated SQL Injection via CUtils.checkSQLInjection()
CVSS 7.6
CVE-2025-34102 CRITICAL
CryptoLog PHP - Unauthenticated Remote Code Execution via SQL Injection and Command Injection
CVE-2025-7411 HIGH
LifeStyle Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-53549 MEDIUM
matrix-sdk 0.11-0.12 - SQL Injection via EventCache::find_event_with_relations
CVE-2025-7410 HIGH
LifeStyle Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7409 HIGH
code-projects Mobile Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6970 HIGH
Events Manager <= 7.0.3 - Unauthenticated Time-Based SQL Injection via Orderby Parameter
CVSS 7.5
CVE-2025-7220 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
Details
Vulnerabilities 19,599
Exploit Likelihood High