CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,612 vulnerabilities with CWE-89
CVE-2025-6847 MEDIUM
Simple Forum 1.0 - SQL Injection via forum_edit.php iii Parameter
CVSS 6.3
CVE-2025-6846 HIGH
Simple Forum 1.0 - SQL Injection via Name Parameter in forum_viewfile.php
CVSS 7.3
CVE-2025-6845 HIGH
code-projects Simple Forum 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6844 HIGH
Simple Forum 1.0 - SQL Injection via User Parameter in signin.php
CVSS 7.3
CVE-2025-6842 MEDIUM
code-projects Product Inventory System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-6841 MEDIUM
Product Inventory System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-6840 HIGH
Product Inventory System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6836 HIGH
code-projects Library System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6835 HIGH
code-projects Library System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6834 HIGH
code-projects Inventory Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6829 MEDIUM
aaluoxiang oa_system <c3a08168 - SQL Injection
CVSS 6.3
CVE-2025-6828 HIGH
Code-projects Inventory Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6827 HIGH
code-projects Inventory Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6826 HIGH
code-projects Payroll Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6823 HIGH
Code-projects Inventory Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6822 HIGH
Code-projects Inventory Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6821 HIGH
code-projects Inventory Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6820 HIGH
Code-projects Inventory Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6819 HIGH
Code-projects Inventory Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6777 HIGH
Food Distributor Site 1.0 - SQL Injection via Username/Password Parameter
CVSS 7.3
CVE-2025-53091 CRITICAL
WeGIA < 3.4.0 - Unauthenticated Time-Based Blind SQL Injection via almox Parameter
CVSS 9.8
CVE-2025-6768 MEDIUM
sfturing hosp_order <627f426331da8086ce8fff2017d65b1ddef384f8 - SQL...
CVSS 6.3
CVE-2025-53306 HIGH
Lucidcrew WP Forum <1.8.2 - SQL Injection
CVSS 7.6
CVE-2025-53258 HIGH
Wow-Company Hover Effects <2.1.2 - SQL Injection
CVSS 7.6
CVE-2025-53256 HIGH
YayCommerce YaySMTP <2.6.5 - SQL Injection
CVSS 7.6
Details
Vulnerabilities 19,612
Exploit Likelihood High