CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,612 vulnerabilities with CWE-89
CVE-2025-6767 MEDIUM
sfturing hosp_order <627f426331da8086ce8fff2017d65b1ddef384f8 - SQL...
CVSS 6.3
CVE-2025-6766 MEDIUM
sfturing hosp_order < 2021-09-03 - SQL Injection via OfficeServiceImpl.java getOfficeName Function
CVSS 6.3
CVE-2025-52834 CRITICAL
Homey <= 2.4.7 - SQL Injection
CVSS 9.3
CVE-2025-52829 CRITICAL
DirectIQ Email Marketing <2.0 - SQL Injection
CVSS 9.3
CVE-2025-52722 CRITICAL
JoinWebs Classiera <4.0.34 - SQL Injection
CVSS 9.3
CVE-2025-52717 CRITICAL
LifterLMS <= 8.0.6 - SQL Injection
CVSS 9.3
CVE-2025-39474 CRITICAL
ThemeMove Amely <= 3.1.4 - SQL Injection
CVSS 9.3
CVE-2025-23967 CRITICAL
wpopal GG Bought Together <1.0.2 - SQL Injection
CVSS 9.3
CVE-2025-6753 MEDIUM
huija bicycleSharingServer 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6749 MEDIUM
huija bicycleSharingServer - SQL Injection
CVSS 6.3
CVE-2025-6738 MEDIUM
huija bicycleSharingServer <7b8a3ba48ad618604abd4797d2e7cf3b5ac7625...
CVSS 6.3
CVE-2025-53122 MEDIUM
OpenNMS Horizon/Meridian - SQL Injection
CVE-2025-51671 MEDIUM
PHPGurukul Dairy Farm Shop Management System 1.3 - SQL Injection via Category Parameters
CVSS 5.4
CVE-2025-51672 HIGH
PHPGurukul Dairy Farm Shop Management System 1.3 - SQL Injection via companyname Parameter
CVSS 8.0
CVE-2025-5590 HIGH
Owl carousel responsive < 1.9 - Authenticated Time-Based SQL Injection via id Parameter
CVSS 8.8
CVE-2025-6668 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via brandId Parameter
CVSS 7.3
CVE-2025-6665 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via editBrandStatus Parameter
CVSS 7.3
CVE-2025-6612 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via categoriesId Parameter
CVSS 7.3
CVE-2025-6611 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via brandStatus Parameter
CVSS 7.3
CVE-2025-6610 MEDIUM
Employee Management System <= 1.0 - SQL Injection via FirstName Parameter in editempprofile.php
CVSS 4.7
CVE-2025-6609 MEDIUM
Best Salon Management System 1.0 - SQL Injection via fromdate/todate Parameter
CVSS 6.3
CVE-2025-6608 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6607 MEDIUM
Best Salon Management System 1.0 - SQL Injection via /panel/stock.php ID Parameter
CVSS 6.3
CVE-2025-6606 MEDIUM
Best Salon Management System 1.0 - SQL Injection via /panel/add-services.php Type Parameter
CVSS 6.3
CVE-2025-6605 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
Details
Vulnerabilities 19,612
Exploit Likelihood High