CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,613 vulnerabilities with CWE-89
CVE-2025-49452
CRITICAL
PostaPanduri <2.1.3 - SQL Injection
CVSS 9.3
CVE-2025-48274
CRITICAL
WP Job Portal <2.3.2 - SQL Injection
CVSS 9.3
CVE-2025-48118
HIGH
WpExperts Hub Woocommerce Partial Shipment <3.2 - SQL Injection
CVSS 8.5
CVE-2025-47573
CRITICAL
Mojoomla School Management <92.0.0 - SQL Injection
CVSS 9.3
CVE-2025-39486
HIGH
ValvePress Rankie < 1.8.2 - SQL Injection
CVSS 8.5
CVE-2025-39479
CRITICAL
smartiolabs Smart Notification <10.3 - SQL Injection
CVSS 9.3
CVE-2025-30562
HIGH
wpdistillery Navigation Tree Elementor <1.0.1 - SQL Injection
CVSS 8.5
CVE-2025-28972
HIGH
Suhas Surse WP Employee Attendance System <3.5 - SQL Injection
CVSS 7.6
CVE-2025-24773
CRITICAL
mojoomla WPCRM <3.2.0 - SQL Injection
CVSS 9.3
CVE-2025-6173
MEDIUM
Webkul QloApps 1.6.1 - SQL Injection via /admin/ajax_products_list.php packItself Parameter
CVSS 4.7
CVE-2025-6160
HIGH
SourceCodester Client Database Management System 1.0 - SQL Injection via user_id Parameter
CVSS 7.3
CVE-2025-6159
HIGH
Hostel Management System 1.0 - SQL Injection via Allocate Room Search Box
CVSS 7.3
CVE-2025-6157
HIGH
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection via testtype Parameter
CVSS 7.3
CVE-2025-6156
MEDIUM
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection via testtype Parameter
CVSS 6.3
CVE-2025-6155
HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6154
HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via student_roll_no Parameter
CVSS 7.3
CVE-2025-6153
HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via Search Box Parameter
CVSS 7.3
CVE-2025-5673
MEDIUM
Blog2Social: Social Media Auto Post & Scheduler <= 8.4.4 - Authenticated SQL Injection via prgSortPostType Parameter
CVSS 6.5
CVE-2025-6136
MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertPayment.php recipt_no Parameter
CVSS 6.3
CVE-2025-6135
MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertNominee.php client_id/nominee_id
CVSS 6.3
CVE-2025-6134
MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertClient.php client_id Parameter
CVSS 6.3
CVE-2025-6133
MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertagent.php agent_id Parameter
CVSS 6.3
CVE-2025-6132
HIGH
Chanjet CRM 1.0 - SQL Injection via gblOrgID Parameter in departmentsetting.php
CVSS 7.3
CVE-2025-6124
HIGH
Restaurant Order System 1.0 - SQL Injection via /tablelow.php ID Parameter
CVSS 7.3
CVE-2025-6123
HIGH
Restaurant Order System 1.0 - SQL Injection via Payment.php tabidNoti Parameter
CVSS 7.3
Details
Vulnerabilities
19,613
Exploit Likelihood
High