CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,612 vulnerabilities with CWE-89
CVE-2025-6891 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via Username Parameter in createUser.php
CVSS 7.3
CVE-2025-6890 MEDIUM
Movie Ticketing System 1.0 - SQL Injection via Date Parameter in ticketConfirmation.php
CVSS 6.3
CVE-2025-6889 HIGH
Movie Ticketing System 1.0 - SQL Injection via postName Parameter in logIn.php
CVSS 7.3
CVE-2025-6888 HIGH
PHPGurukul Teachers Record Management System 2.1 - SQL Injection via tid Parameter
CVSS 7.3
CVE-2025-6885 HIGH
PHPGurukul Teachers Record Management System 2.1 - SQL Injection via tid Parameter
CVSS 7.3
CVE-2025-6884 MEDIUM
Staff Audit System 1.0 - SQL Injection via Search Parameter in search_index.php
CVSS 6.3
CVE-2025-6883 MEDIUM
Staff Audit System 1.0 - SQL Injection via updateid Parameter
CVSS 6.3
CVE-2025-6880 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6879 MEDIUM
Best Salon Management System 1.0 - SQL Injection via Name Parameter in /panel/add-tax.php
CVSS 6.3
CVE-2025-6878 MEDIUM
Best Salon Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 6.3
CVE-2025-6877 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6876 MEDIUM
Best Salon Management System 1.0 - SQL Injection via Name Parameter in /panel/add-category.php
CVSS 6.3
CVE-2025-6875 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6874 MEDIUM
Best Salon Management System 1.0 - SQL Injection via user_id/plan_id Parameter
CVSS 6.3
CVE-2025-6871 HIGH
Simple Company Website 1.0 - SQL Injection via Username Parameter in Login.php
CVSS 7.3
CVE-2025-6869 MEDIUM
SourceCodester Simple Company Website 1.0 - SQL Injection via /admin/testimonials/manage.php ID Parameter
CVSS 4.7
CVE-2025-24290 CRITICAL
UISP Application <= 2.4.206 - Authenticated SQL Injection
CVSS 9.9
CVE-2025-6868 MEDIUM
SourceCodester Simple Company Website 1.0 - SQL Injection via ID Parameter in manage.php
CVSS 4.7
CVE-2025-6867 MEDIUM
SourceCodester Simple Company Website 1.0 - SQL Injection
CVSS 4.7
CVE-2025-6863 HIGH
PHPGurukul Local Services Search Engine Management System 2.1 - SQL Injection via editid Parameter
CVSS 7.3
CVE-2025-6862 MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6861 MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6860 MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6859 MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6850 MEDIUM
Simple Forum 1.0 - SQL Injection via File Parameter in forum1.php
CVSS 6.3
Details
Vulnerabilities 19,612
Exploit Likelihood High