CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,613 vulnerabilities with CWE-89
CVE-2025-49452 CRITICAL
PostaPanduri <2.1.3 - SQL Injection
CVSS 9.3
CVE-2025-48274 CRITICAL
WP Job Portal <2.3.2 - SQL Injection
CVSS 9.3
CVE-2025-48118 HIGH
WpExperts Hub Woocommerce Partial Shipment <3.2 - SQL Injection
CVSS 8.5
CVE-2025-47573 CRITICAL
Mojoomla School Management <92.0.0 - SQL Injection
CVSS 9.3
CVE-2025-39486 HIGH
ValvePress Rankie < 1.8.2 - SQL Injection
CVSS 8.5
CVE-2025-39479 CRITICAL
smartiolabs Smart Notification <10.3 - SQL Injection
CVSS 9.3
CVE-2025-30562 HIGH
wpdistillery Navigation Tree Elementor <1.0.1 - SQL Injection
CVSS 8.5
CVE-2025-28972 HIGH
Suhas Surse WP Employee Attendance System <3.5 - SQL Injection
CVSS 7.6
CVE-2025-24773 CRITICAL
mojoomla WPCRM <3.2.0 - SQL Injection
CVSS 9.3
CVE-2025-6173 MEDIUM
Webkul QloApps 1.6.1 - SQL Injection via /admin/ajax_products_list.php packItself Parameter
CVSS 4.7
CVE-2025-6160 HIGH
SourceCodester Client Database Management System 1.0 - SQL Injection via user_id Parameter
CVSS 7.3
CVE-2025-6159 HIGH
Hostel Management System 1.0 - SQL Injection via Allocate Room Search Box
CVSS 7.3
CVE-2025-6157 HIGH
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection via testtype Parameter
CVSS 7.3
CVE-2025-6156 MEDIUM
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection via testtype Parameter
CVSS 6.3
CVE-2025-6155 HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6154 HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via student_roll_no Parameter
CVSS 7.3
CVE-2025-6153 HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via Search Box Parameter
CVSS 7.3
CVE-2025-5673 MEDIUM
Blog2Social: Social Media Auto Post & Scheduler <= 8.4.4 - Authenticated SQL Injection via prgSortPostType Parameter
CVSS 6.5
CVE-2025-6136 MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertPayment.php recipt_no Parameter
CVSS 6.3
CVE-2025-6135 MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertNominee.php client_id/nominee_id
CVSS 6.3
CVE-2025-6134 MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertClient.php client_id Parameter
CVSS 6.3
CVE-2025-6133 MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertagent.php agent_id Parameter
CVSS 6.3
CVE-2025-6132 HIGH
Chanjet CRM 1.0 - SQL Injection via gblOrgID Parameter in departmentsetting.php
CVSS 7.3
CVE-2025-6124 HIGH
Restaurant Order System 1.0 - SQL Injection via /tablelow.php ID Parameter
CVSS 7.3
CVE-2025-6123 HIGH
Restaurant Order System 1.0 - SQL Injection via Payment.php tabidNoti Parameter
CVSS 7.3
Details
Vulnerabilities 19,613
Exploit Likelihood High