CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,612 vulnerabilities with CWE-89
CVE-2025-6310 HIGH
PHPGurukul Emergency Ambulance Hiring Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6309 MEDIUM
PHPGurukul Emergency Ambulance Hiring Portal 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6308 MEDIUM
PHPGurukul Emergency Ambulance Hiring Portal 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6307 HIGH
code-projects Online Shoe Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6306 HIGH
Online Shoe Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6305 HIGH
code-projects Online Shoe Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6304 HIGH
code-projects Online Shoe Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6303 HIGH
code-projects Online Shoe Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6300 HIGH
PHPGurukul Employee Record Management System 1.3 - SQL Injection
CVSS 7.3
CVE-2025-6296 HIGH
Hostel Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6295 HIGH
Hostel Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6294 HIGH
Hostel Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6293 HIGH
Hostel Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6277 MEDIUM
Brilliance Golden Link Secondary System <20250609 - SQL Injection
CVSS 6.3
CVE-2025-6276 MEDIUM
Brilliance Golden Link Secondary System <20250609 - SQL Injection
CVSS 6.3
CVE-2025-6267 MEDIUM
ADP Application Developer Platform 1.0.0 - SQL Injection
CVSS 6.3
CVE-2025-4738 CRITICAL
Yirmibes Software MY ERP <1.170 - SQL Injection
CVSS 9.8
CVE-2025-52474 CRITICAL
WeGIA < 3.4.2 - SQL Injection via id Parameter in control.php Endpoint
CVSS 9.8
CVE-2025-26198 CRITICAL
CloudClassroom-PHP-Project v1.0 - Unauthenticated SQL Injection via Admin Login Username Field
CVSS 9.8
CVE-2025-46109 HIGH
pbootcms 3.2.5-3.2.10 - SQL Injection via Crafted GET Request
CVSS 8.8
CVE-2025-49218 HIGH
Trend Micro Endpoint Encryption < 6.0.0.4013 - Authenticated SQL Injection
CVSS 7.7
CVE-2025-49215 HIGH
Trend Micro Endpoint Encryption < 6.0.0.4013 - Authenticated SQL Injection
CVSS 8.8
CVE-2025-49211 HIGH
Trend Micro Endpoint Encryption < 6.0.0.4013 - SQL Injection
CVSS 7.7
CVE-2025-49854 HIGH
Anh Tran Slim SEO <4.5.4 - SQL Injection
CVSS 7.6
CVE-2025-49452 CRITICAL
PostaPanduri <2.1.3 - SQL Injection
CVSS 9.3
Details
Vulnerabilities 19,612
Exploit Likelihood High