CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,599 vulnerabilities with CWE-89
CVE-2025-7219 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7218 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7217 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7212 MEDIUM
Insurance Management System <= 1.0 - SQL Injection via agent_id Parameter in insertAgent.php
CVSS 6.3
CVE-2025-7211 HIGH
LifeStyle Store 1.0 - SQL Injection via /cart_add.php ID Parameter
CVSS 7.3
CVE-2025-7200 MEDIUM
krishna9772 pharmacy_management_system < 2024-03-06 - SQL Injection via med_name/med_cat/ex_date Parameters
CVSS 6.3
CVE-2025-7199 HIGH
code-projects Library System 1.0 - SQL Injection via /notapprove.php ID Parameter
CVSS 7.3
CVE-2025-7198 HIGH
Jonnys Liquor 1.0 - SQL Injection via Drink Parameter
CVSS 7.3
CVE-2025-7197 HIGH
Jonnys Liquor 1.0 - SQL Injection via ID Parameter in /admin/delete-row.php
CVSS 7.3
CVE-2025-7196 HIGH
Jonnys Liquor 1.0 - SQL Injection via Search Parameter
CVSS 7.3
CVE-2025-7193 HIGH
Agri-Trading Online Shopping System <= 1.0 - SQL Injection via Supplier Parameter
CVSS 7.3
CVE-2025-7191 HIGH
code-projects Student Enrollment System 1.0 - SQL Injection via Username Parameter in login.php
CVSS 7.3
CVE-2025-7189 MEDIUM
code-projects Chat System 1.0 - SQL Injection via msg Parameter in send_message.php
CVSS 6.3
CVE-2025-7188 MEDIUM
code-projects Chat System 1.0 - SQL Injection via ID Parameter in addmember.php
CVSS 6.3
CVE-2025-7187 MEDIUM
code-projects Chat System 1.0 - SQL Injection via fetch_member.php ID Parameter
CVSS 6.3
CVE-2025-7186 MEDIUM
code-projects Chat System 1.0 - SQL Injection via ID Parameter in fetch_chat.php
CVSS 6.3
CVE-2025-47178 HIGH
Microsoft Configuration Manager 2503 < 5.00.9135.1003 - Authenticated SQL Injection
CVSS 8.0
CVE-2025-7185 HIGH
code-projects Library System 1.0 - SQL Injection via /approve.php ID Parameter
CVSS 7.3
CVE-2025-7184 HIGH
code-projects Library System 1.0 - SQL Injection via Search Parameter
CVSS 7.3
CVE-2025-7183 HIGH
Campcodes Sales and Inventory System 1.0 - SQL Injection via Customer Parameter
CVSS 7.3
CVE-2025-7037 HIGH
Ivanti Endpoint Manager < 2024 SU3 and < 2022 SU8 Security Update 1 - Authenticated SQL Injection
CVSS 7.2
CVE-2025-29267 MEDIUM
Abis, Inc Adjutant Core Accounting ERP <v.PreBeta250F - Info Disclo...
CVSS 6.5
CVE-2025-24474 LOW
FortiAnalyzer and FortiManager 6.4-7.6.1 - Authenticated SQL Injection
CVSS 2.7
CVE-2025-7180 HIGH
Staff Audit System 1.0 - SQL Injection via User Parameter in Login
CVSS 7.3
CVE-2025-7179 HIGH
code-projects Library System 1.0 - SQL Injection via Username Parameter in add-teacher.php
CVSS 7.3
Details
Vulnerabilities 19,599
Exploit Likelihood High