CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,599 vulnerabilities with CWE-89
CVE-2025-7475
HIGH
Simple Car Rental System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7474
HIGH
Job Diary 1.0 - SQL Injection via Search Parameter in /search.php
CVSS 7.3
CVE-2025-7471
HIGH
code-projects Modern Bag 1.0 - SQL Injection via /admin/login-back.php user-name Parameter
CVSS 7.3
CVE-2025-7469
HIGH
Campcodes Sales and Inventory System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7467
HIGH
code-projects Modern Bag 1.0 - SQL Injection via /product-detail.php ID Parameter
CVSS 7.3
CVE-2025-7466
HIGH
1000projects ABC Courier Management 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7461
HIGH
code-projects Modern Bag 1.0 - SQL Injection via proId Parameter in /action.php
CVSS 7.3
CVE-2025-7459
HIGH
code-projects Mobile Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7457
HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via ID Parameter in manage_movie.php
CVSS 7.3
CVE-2025-7456
HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via Reserve.php ID Parameter
CVSS 7.3
CVE-2025-7455
HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via /manage_reserve.php mid Parameter
CVSS 7.3
CVE-2025-7454
HIGH
Campcodes Online Movie Theater Seat Reservation System 1.0 - SQL Injection via /admin/manage_theater.php ID Parameter
CVSS 7.3
CVE-2025-7442
HIGH
WPGYM - Wordpress Gym Management System <67.8.0 - SQL Injection
CVSS 7.5
CVE-2025-7436
HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-53515
HIGH
Advantech iView - SQL Injection, RCE
CVSS 8.8
CVE-2025-53475
HIGH
Advantech iView - SQL Injection, RCE
CVSS 8.8
CVE-2025-52577
HIGH
Advantech iView < 5.7.05.7057 - SQLi & RCE via NetworkServlet.archiveTrapRange()
CVSS 8.8
CVE-2025-48891
HIGH
Advantech iView < 5.7.05.7057 - Authenticated SQL Injection via CUtils.checkSQLInjection()
CVSS 7.6
CVE-2025-34102
CRITICAL
CryptoLog PHP - Unauthenticated Remote Code Execution via SQL Injection and Command Injection
CVE-2025-7411
HIGH
LifeStyle Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-53549
MEDIUM
matrix-sdk 0.11-0.12 - SQL Injection via EventCache::find_event_with_relations
CVE-2025-7410
HIGH
LifeStyle Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-7409
HIGH
code-projects Mobile Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6970
HIGH
Events Manager <= 7.0.3 - Unauthenticated Time-Based SQL Injection via Orderby Parameter
CVSS 7.5
CVE-2025-7220
HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
Details
Vulnerabilities
19,599
Exploit Likelihood
High