CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,613 vulnerabilities with CWE-89
CVE-2025-47172 HIGH
Microsoft SharePoint Enterprise Server - Authenticated SQL Injection
CVSS 8.8
CVE-2025-49455 CRITICAL
TinySalt <3.10.0 - Code Injection
CVSS 9.3
CVE-2025-40657 CRITICAL
DM Corporative CMS < 2025.01 - SQL Injection via codform Parameter
CVSS 9.8
CVE-2025-40656 CRITICAL
DM Corporative CMS < 2025.01 - SQL Injection via cod Parameter
CVSS 9.8
CVE-2025-40655 CRITICAL
DM Corporative CMS < 2025.01 - SQL Injection via /antcatalogue.asp Name Parameter
CVSS 9.8
CVE-2025-40654 CRITICAL
DM Corporative CMS < 2025.01 - SQL Injection via name and cod Parameters
CVSS 9.8
CVE-2025-4840 HIGH
inprosysmedia-likes-dislikes-post WordPress Plugin < 1.0.0 - Unauthenticated SQL Injection via AJAX Action
CVSS 7.5
CVE-2025-5913 HIGH
PHPGurukul Vehicle Record Management System 1.0 - SQL Injection via searchinputdata Parameter
CVSS 7.3
CVE-2025-30507 MEDIUM
CyberData 011209 Intercom - Info Disclosure
CVSS 5.3
CVE-2025-48281 CRITICAL
mystyleplatform <3.21.1 - SQL Injection
CVSS 9.3
CVE-2025-48141 CRITICAL
Alex Zaytseff Multi CryptoCurrency Payments <2.0.3 - SQL Injection
CVSS 9.3
CVE-2025-48122 CRITICAL
Holest Engineering Spreadsheet Price Changer <2.4.37 - SQL Injection
CVSS 9.3
CVE-2025-47651 HIGH
Infility Global <2.12.4 - SQL Injection
CVSS 8.5
CVE-2025-47608 CRITICAL
sonalsinha21 Recover abandoned cart for WooCommerce <2.5 - SQL Injection
CVSS 9.3
CVE-2025-31920 HIGH
AmentoTech WP Guppy <4.3.3 - SQL Injection
CVSS 8.5
CVE-2025-31424 CRITICAL
WP Lead Capturing Pages <2.3 - SQL Injection
CVSS 9.3
CVE-2025-31059 CRITICAL
woobewoo WBW Product Table PRO <2.1.3 - SQL Injection
CVSS 9.3
CVE-2025-24767 CRITICAL
TicketBAI Facturas para WooCommerce <3.19 - SQL Injection
CVSS 9.3
CVE-2025-5881 MEDIUM
code-projects Chat System <= 1.0 - SQL Injection via Confirm Password cid Parameter
CVSS 6.3
CVE-2025-41444 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Alerts Module
CVSS 8.3
CVE-2025-36528 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Service Account Auditing Reports
CVSS 8.3
CVE-2025-27709 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Service Account Auditing Reports
CVSS 8.3
CVE-2025-5860 HIGH
PHPGurukul Maid Hiring Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5859 MEDIUM
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-5858 MEDIUM
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection
CVSS 6.3
Details
Vulnerabilities 19,613
Exploit Likelihood High