CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,613 vulnerabilities with CWE-89
CVE-2025-6122 MEDIUM
Restaurant Order System 1.0 - SQL Injection via /table.php ID Parameter
CVSS 6.3
CVE-2025-6118 HIGH
Das Parking Management System 6.2.0 - SQL Injection via vehicleTypeCode Parameter
CVSS 7.3
CVE-2025-6117 HIGH
Das Parking Management System 6.2.0 - SQL Injection via Reservations Search API Value Parameter
CVSS 7.3
CVE-2025-6116 HIGH
Das Parking Management System 6.2.0 - SQL Injection via /IntraFieldVehicle/Search Value Parameter
CVSS 7.3
CVE-2025-40728 HIGH
Customer Support System 1.0 - Authenticated SQL Injection via id Parameter
CVSS 8.8
CVE-2025-6169 CRITICAL
HAMASTAR Technology WIMP < 5.3.1.34642 - Unauthenticated SQL Injection
CVSS 9.8
CVE-2025-6100 MEDIUM
realguoshuai open-video-cms 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6096 MEDIUM
Jasmin Ransomware <1.0.1 - SQL Injection
CVSS 6.3
CVE-2025-6095 HIGH
Jasmin Ransomware 1.0.1 - SQL Injection
CVSS 7.3
CVE-2025-6094 MEDIUM
qianfox FoxCMS <1.2.5 - SQL Injection
CVSS 6.3
CVE-2025-5487 HIGH
AutomatorWP - Time-Based SQL Injection
CVSS 7.2
CVE-2025-49468 HIGH
No Boss Calendar <5.0.7 - SQL Injection
CVE-2025-41233 MEDIUM
VMware AVI Load Balancer - Authenticated SQL Injection
CVSS 6.8
CVE-2025-49467 CRITICAL
Joomla JEvents <3.6.88, <3.6.82.1 - SQL Injection
CVE-2025-29744 MEDIUM
pg-promise < 11.5.5 - SQL Injection via Negative Number Handling
CVSS 5.4
CVE-2025-6009 MEDIUM
kiCode111 like-girl <5.2.0 - SQL Injection
CVSS 4.7
CVE-2025-6008 MEDIUM
kiCode111 like-girl <5.2.0 - SQL Injection
CVSS 4.7
CVE-2025-6007 MEDIUM
kiCode111 like-girl 5.2.0 - SQL Injection
CVSS 4.7
CVE-2025-6006 MEDIUM
kiCode111 like-girl 5.2.0 - SQL Injection
CVSS 4.7
CVE-2025-6005 MEDIUM
kiCode111 like-girl 5.2.0 - SQL Injection
CVSS 4.7
CVE-2025-32466 MEDIUM
RSMediaGallery! 1.7.4-2.1.7 - SQL Injection
CVE-2025-5980 HIGH
Restaurant Order System 1.0 - SQL Injection via tabidNoti Parameter
CVSS 7.3
CVE-2025-5979 HIGH
School Fees Payment System 1.0 - SQL Injection via ID Parameter in /branch.php
CVSS 7.3
CVE-2025-5977 HIGH
School Fees Payment System 1.0 - SQL Injection via sSortDir_0 Parameter in datatable.php
CVSS 7.3
CVE-2025-5971 MEDIUM
School Fees Payment System 1.0 - SQL Injection via ajx.php name_startsWith Parameter
CVSS 6.3
Details
Vulnerabilities 19,613
Exploit Likelihood High