CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,613 vulnerabilities with CWE-89
CVE-2025-47172
HIGH
Microsoft SharePoint Enterprise Server - Authenticated SQL Injection
CVSS 8.8
CVE-2025-49455
CRITICAL
TinySalt <3.10.0 - Code Injection
CVSS 9.3
CVE-2025-40657
CRITICAL
DM Corporative CMS < 2025.01 - SQL Injection via codform Parameter
CVSS 9.8
CVE-2025-40656
CRITICAL
DM Corporative CMS < 2025.01 - SQL Injection via cod Parameter
CVSS 9.8
CVE-2025-40655
CRITICAL
DM Corporative CMS < 2025.01 - SQL Injection via /antcatalogue.asp Name Parameter
CVSS 9.8
CVE-2025-40654
CRITICAL
DM Corporative CMS < 2025.01 - SQL Injection via name and cod Parameters
CVSS 9.8
CVE-2025-4840
HIGH
inprosysmedia-likes-dislikes-post WordPress Plugin < 1.0.0 - Unauthenticated SQL Injection via AJAX Action
CVSS 7.5
CVE-2025-5913
HIGH
PHPGurukul Vehicle Record Management System 1.0 - SQL Injection via searchinputdata Parameter
CVSS 7.3
CVE-2025-30507
MEDIUM
CyberData 011209 Intercom - Info Disclosure
CVSS 5.3
CVE-2025-48281
CRITICAL
mystyleplatform <3.21.1 - SQL Injection
CVSS 9.3
CVE-2025-48141
CRITICAL
Alex Zaytseff Multi CryptoCurrency Payments <2.0.3 - SQL Injection
CVSS 9.3
CVE-2025-48122
CRITICAL
Holest Engineering Spreadsheet Price Changer <2.4.37 - SQL Injection
CVSS 9.3
CVE-2025-47651
HIGH
Infility Global <2.12.4 - SQL Injection
CVSS 8.5
CVE-2025-47608
CRITICAL
sonalsinha21 Recover abandoned cart for WooCommerce <2.5 - SQL Injection
CVSS 9.3
CVE-2025-31920
HIGH
AmentoTech WP Guppy <4.3.3 - SQL Injection
CVSS 8.5
CVE-2025-31424
CRITICAL
WP Lead Capturing Pages <2.3 - SQL Injection
CVSS 9.3
CVE-2025-31059
CRITICAL
woobewoo WBW Product Table PRO <2.1.3 - SQL Injection
CVSS 9.3
CVE-2025-24767
CRITICAL
TicketBAI Facturas para WooCommerce <3.19 - SQL Injection
CVSS 9.3
CVE-2025-5881
MEDIUM
code-projects Chat System <= 1.0 - SQL Injection via Confirm Password cid Parameter
CVSS 6.3
CVE-2025-41444
HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Alerts Module
CVSS 8.3
CVE-2025-36528
HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Service Account Auditing Reports
CVSS 8.3
CVE-2025-27709
HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Service Account Auditing Reports
CVSS 8.3
CVE-2025-5860
HIGH
PHPGurukul Maid Hiring Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5859
MEDIUM
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-5858
MEDIUM
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection
CVSS 6.3
Details
Vulnerabilities
19,613
Exploit Likelihood
High