CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,612 vulnerabilities with CWE-89
CVE-2025-53529
CRITICAL
WeGIA < 3.4.3 - Unauthenticated SQL Injection via id_funcionario Parameter
CVSS 9.8
CVE-2025-53527
CRITICAL
WeGIA - Time-Based Blind SQL Injection via almox Parameter
CVSS 9.8
CVE-2025-7135
HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection via ID Parameter in save_vacancy Action
CVSS 7.3
CVE-2025-7134
HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection via ID Parameter in Delete Application
CVSS 7.3
CVE-2025-45065
CRITICAL
Employee Record Management System in PHP and MySQL v1 - SQL Injection via loginerms.php Endpoint
CVSS 9.8
CVE-2025-7132
HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7131
HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via employee_id Parameter in save_employee_attendance
CVSS 7.3
CVE-2025-7130
HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7129
HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via ID Parameter in delete_employee_attendance_single
CVSS 7.3
CVE-2025-7128
HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-7127
MEDIUM
Employee Management System <= 1.0 - SQL Injection via currentpassword Parameter
CVSS 4.7
CVE-2025-7126
MEDIUM
Employee Management System <= 1.0 - SQL Injection via AdminName Parameter
CVSS 6.3
CVE-2025-7125
MEDIUM
Employee Management System <= 1.0 - SQL Injection via coursepg Parameter
CVSS 6.3
CVE-2025-7123
MEDIUM
Campcodes Complaint Management System 1.0 - SQL Injection via cid/uid Parameter
CVSS 4.7
CVE-2025-7122
HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2025-7121
MEDIUM
Campcodes Complaint Management System 1.0 - SQL Injection via Complaint ID Parameter
CVSS 6.3
CVE-2025-7120
HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Email Parameter in check_availability.php
CVSS 7.3
CVE-2025-7119
HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Username Parameter in /users/index.php
CVSS 7.3
CVE-2025-7102
MEDIUM
BoyunCMS < 1.4.20 - SQL Injection via Phone Parameter in Server.php
CVSS 6.3
CVE-2025-52833
CRITICAL
designthemes LMS <9.1 - SQL Injection
CVSS 9.3
CVE-2025-52832
CRITICAL
wpo-HR NGG Smart Image Search <3.4.1 - SQL Injection
CVSS 9.3
CVE-2025-52831
CRITICAL
Video List Manager <1.7 - SQL Injection
CVSS 9.3
CVE-2025-52830
CRITICAL
bSecure - Your Universal Checkout <= 1.7.9 - Blind SQL Injection
CVSS 9.3
CVE-2025-49870
HIGH
Cozmoslabs Paid Member Subscriptions <2.15.1 - SQL Injection
CVSS 7.5
CVE-2025-32297
HIGH
quantumcloud Simple Link Directory <14.7.3 - SQL Injection
CVSS 8.5
Details
Vulnerabilities
19,612
Exploit Likelihood
High