CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,612 vulnerabilities with CWE-89
CVE-2025-6474 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via user_id Parameter
CVSS 7.3
CVE-2025-6472 HIGH
Online Bidding System 1.0 - SQL Injection via showprod.php ID Parameter
CVSS 7.3
CVE-2025-6471 HIGH
Online Bidding System 1.0 - SQL Injection via aduser Parameter
CVSS 7.3
CVE-2025-6470 HIGH
Online Bidding System 1.0 - SQL Injection via ID Parameter in bidlog.php
CVSS 7.3
CVE-2025-6469 HIGH
Online Bidding System 1.0 - SQL Injection via ID Parameter in details.php
CVSS 7.3
CVE-2025-6468 HIGH
Online Bidding System 1.0 - SQL Injection via ID Parameter in bidnow.php
CVSS 7.3
CVE-2025-6467 HIGH
Online Bidding System 1.0 - SQL Injection via User Parameter in login.php
CVSS 7.3
CVE-2025-6458 HIGH
Online Hotel Reservation System 1.0 - SQL Injection via userid Parameter
CVSS 7.3
CVE-2025-6457 HIGH
Online Hotel Reservation System 1.0 - SQL Injection via Start Parameter in /reservation/demo.php
CVSS 7.3
CVE-2025-6456 HIGH
Online Hotel Reservation System 1.0 - SQL Injection via Start Parameter in /reservation/order.php
CVSS 7.3
CVE-2025-6455 HIGH
Online Hotel Reservation System 1.0 - SQL Injection via Name Parameter in /messageexec.php
CVSS 7.3
CVE-2025-6451 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2025-6450 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2025-6449 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2025-6448 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via /admin/delete_room.php room_id Parameter
CVSS 7.3
CVE-2025-6447 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6446 HIGH
Client Details System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6421 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via /admin/add_account.php name/admin_id Parameter
CVSS 7.3
CVE-2025-6420 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via room_type Parameter
CVSS 7.3
CVE-2025-6419 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via room_type Parameter
CVSS 7.3
CVE-2025-6418 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via Name Parameter in Edit Query Account
CVSS 7.3
CVE-2025-6417 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via Award Details Parameter
CVSS 6.3
CVE-2025-6416 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6415 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6414 MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
Details
Vulnerabilities 19,612
Exploit Likelihood High