CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,612 vulnerabilities with CWE-89
CVE-2025-53529 CRITICAL
WeGIA < 3.4.3 - Unauthenticated SQL Injection via id_funcionario Parameter
CVSS 9.8
CVE-2025-53527 CRITICAL
WeGIA - Time-Based Blind SQL Injection via almox Parameter
CVSS 9.8
CVE-2025-7135 HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection via ID Parameter in save_vacancy Action
CVSS 7.3
CVE-2025-7134 HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection via ID Parameter in Delete Application
CVSS 7.3
CVE-2025-45065 CRITICAL
Employee Record Management System in PHP and MySQL v1 - SQL Injection via loginerms.php Endpoint
CVSS 9.8
CVE-2025-7132 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7131 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via employee_id Parameter in save_employee_attendance
CVSS 7.3
CVE-2025-7130 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7129 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via ID Parameter in delete_employee_attendance_single
CVSS 7.3
CVE-2025-7128 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-7127 MEDIUM
Employee Management System <= 1.0 - SQL Injection via currentpassword Parameter
CVSS 4.7
CVE-2025-7126 MEDIUM
Employee Management System <= 1.0 - SQL Injection via AdminName Parameter
CVSS 6.3
CVE-2025-7125 MEDIUM
Employee Management System <= 1.0 - SQL Injection via coursepg Parameter
CVSS 6.3
CVE-2025-7123 MEDIUM
Campcodes Complaint Management System 1.0 - SQL Injection via cid/uid Parameter
CVSS 4.7
CVE-2025-7122 HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2025-7121 MEDIUM
Campcodes Complaint Management System 1.0 - SQL Injection via Complaint ID Parameter
CVSS 6.3
CVE-2025-7120 HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Email Parameter in check_availability.php
CVSS 7.3
CVE-2025-7119 HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Username Parameter in /users/index.php
CVSS 7.3
CVE-2025-7102 MEDIUM
BoyunCMS < 1.4.20 - SQL Injection via Phone Parameter in Server.php
CVSS 6.3
CVE-2025-52833 CRITICAL
designthemes LMS <9.1 - SQL Injection
CVSS 9.3
CVE-2025-52832 CRITICAL
wpo-HR NGG Smart Image Search <3.4.1 - SQL Injection
CVSS 9.3
CVE-2025-52831 CRITICAL
Video List Manager <1.7 - SQL Injection
CVSS 9.3
CVE-2025-52830 CRITICAL
bSecure - Your Universal Checkout <= 1.7.9 - Blind SQL Injection
CVSS 9.3
CVE-2025-49870 HIGH
Cozmoslabs Paid Member Subscriptions <2.15.1 - SQL Injection
CVSS 7.5
CVE-2025-32297 HIGH
quantumcloud Simple Link Directory <14.7.3 - SQL Injection
CVSS 8.5
Details
Vulnerabilities 19,612
Exploit Likelihood High