CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,618 vulnerabilities with CWE-89
CVE-2025-5627
MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection via sputum_form.php itr_no Parameter
CVSS 6.3
CVE-2025-5626
HIGH
Campcodes Online Teacher Record Management System 1.0 - SQL Injection via editid Parameter
CVSS 7.3
CVE-2025-5625
HIGH
Campcodes Online Teacher Record Management System 1.0 - SQL Injection via searchteacher Parameter
CVSS 7.3
CVE-2025-5618
MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection via teamid Parameter
CVSS 6.3
CVE-2025-5617
MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection via teamid Parameter
CVSS 6.3
CVE-2025-5616
MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection via mobilenumber Parameter
CVSS 6.3
CVE-2025-5615
MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection via requestid Parameter
CVSS 6.3
CVE-2025-5614
MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection via searchdata Parameter
CVSS 6.3
CVE-2025-5613
MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection via requestid Parameter
CVSS 6.3
CVE-2025-5612
MEDIUM
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection via Reporting Fullname Parameter
CVSS 6.3
CVE-2025-5611
MEDIUM
CodeAstro Real Estate Management System 1.0 - SQL Injection via /submitpropertyupdate.php ID Parameter
CVSS 6.3
CVE-2025-5610
MEDIUM
CodeAstro Real Estate Management System 1.0 - SQL Injection via /submitpropertydelete.php ID Parameter
CVSS 6.3
CVE-2025-46011
MEDIUM
listmonk 2.4.0-4.1.0 - SQL Injection in QuerySubscribers Function
CVSS 6.5
CVE-2025-5604
HIGH
Campcodes Hospital Management System 1.0 - SQL Injection via Username Parameter in /user-login.php
CVSS 7.3
CVE-2025-5603
HIGH
Campcodes Hospital Management System 1.0 - SQL Injection via Registration Full Name/Username Parameter
CVSS 7.3
CVE-2025-5602
HIGH
Campcodes Hospital Management System 1.0 - SQL Injection via Admin Registration Full Name Parameter
CVSS 7.3
CVE-2025-5599
HIGH
PHPGurukul Student Result Management System 1.3 - SQL Injection
CVSS 7.3
CVE-2025-5583
HIGH
CodeAstro Real Estate Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5582
MEDIUM
CodeAstro Real Estate Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-5581
HIGH
CodeAstro Real Estate Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5580
HIGH
CodeAstro Real Estate Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5579
HIGH
PHPGurukul Dairy Farm Shop Management System 1.3 - SQL Injection
CVSS 7.3
CVE-2025-5578
HIGH
PHPGurukul Dairy Farm Shop Management System 1.3 - SQL Injection
CVSS 7.3
CVE-2025-5577
HIGH
PHPGurukul Dairy Farm Shop Management System 1.3 - SQL Injection
CVSS 7.3
CVE-2025-5576
HIGH
PHPGurukul Dairy Farm Shop Management System 1.3 - SQL Injection
CVSS 7.3
Details
Vulnerabilities
19,618
Exploit Likelihood
High