CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,613 vulnerabilities with CWE-89
CVE-2025-5857 MEDIUM
Code-projects Patient Record Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-5856 HIGH
PHPGurukul BP Monitoring Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5838 MEDIUM
PHPGurukul Employee Record Management System 1.3 - SQL Injection
CVSS 6.3
CVE-2025-5837 MEDIUM
PHPGurukul Employee Record Management System 1.3 - SQL Injection
CVSS 6.3
CVE-2025-5784 MEDIUM
PHPGurukul Employee Record Management System 1.3 - SQL Injection via emp3ctc Parameter in myexp.php
CVSS 6.3
CVE-2025-5783 MEDIUM
PHPGurukul Employee Record Management System 1.3 - SQL Injection via emp3workduration Parameter
CVSS 6.3
CVE-2025-29892 HIGH
Qsync Central <4.5.0.6 - SQL Injection
CVSS 8.8
CVE-2025-5782 MEDIUM
PHPGurukul Employee Record Management System 1.3 - SQL Injection via Reset Password New Password Parameter
CVSS 6.3
CVE-2025-5780 MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection via view_dental.php itr_no Parameter
CVSS 6.3
CVE-2025-5779 MEDIUM
Patient Record Management System 1.0 - SQL Injection via birthing.php itr_no/comp_id Parameter
CVSS 6.3
CVE-2025-5778 HIGH
1000 Projects ABC Courier Management System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-49421 HIGH
WP Text Expander <1.0.1 - SQL Injection
CVSS 7.6
CVE-2025-49328 HIGH
Agile Logix Store Locator <1.5.1 - SQL Injection
CVSS 7.6
CVE-2025-49327 HIGH
Ruben Garcia ShortLinks Pro <1.0.8 - SQL Injection
CVSS 7.6
CVE-2025-49326 HIGH
GamiPress <= 7.4.5 - SQL Injection
CVSS 7.6
CVE-2025-49323 HIGH
Themefic Hydra Booking <1.1.10 - SQL Injection
CVSS 8.5
CVE-2025-49315 HIGH
PersianScript Persian Woocommerce SMS <7.0.10 - SQL Injection
CVSS 7.6
CVE-2025-49263 HIGH
WC Vendors WC Vendors Marketplace <2.5.6 - SQL Injection
CVSS 7.6
CVE-2025-30989 HIGH
Renzo Tejada Libro de Reclamaciones y Quejas <0.9 - SQL Injection
CVSS 7.6
CVE-2025-26590 HIGH
Nir Complete Google Seo Scan <3.5.1 - SQL Injection
CVSS 7.6
CVE-2025-5762 MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection via view_hematology.php itr_no Parameter
CVSS 6.3
CVE-2025-5761 MEDIUM
PHPGurukul BP Monitoring Management System 1.0 - SQL Injection via memberage Parameter
CVSS 6.3
CVE-2025-5759 HIGH
PHPGurukul Local Services Search Engine Management System 2.1 - SQL Injection via editid Parameter
CVSS 7.3
CVE-2025-5758 HIGH
Open Source Clinic Management System 1.0 - SQL Injection via Doctor Name Parameter
CVSS 7.3
CVE-2025-5756 HIGH
Real Estate Property Management System 1.0 - SQL Injection via EditCity.php
CVSS 7.3
Details
Vulnerabilities 19,613
Exploit Likelihood High