CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,618 vulnerabilities with CWE-89
CVE-2025-48949
CRITICAL
navidrome 0.55.0-0.55.2 - SQL Injection via API Artist Endpoint Role Parameter
CVSS 9.8
CVE-2025-5359
HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via ID Parameter in /appointment-history.php
CVSS 7.3
CVE-2025-5358
HIGH
PHPGurukul Cyber Cafe Management System 1.0 - SQL Injection via fromdate/todate Parameters
CVSS 7.3
CVE-2025-48912
MEDIUM
Apache Superset <4.1.2 - Privilege Escalation
CVSS 6.5
CVE-2025-5332
HIGH
1000 Projects Online Notice Board 1.0 - SQL Injection via Email Parameter
CVSS 7.3
CVE-2025-5298
HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via fromdate/todate Parameter
CVSS 7.3
CVE-2025-5287
HIGH
Likes and Dislikes Plugin <1.0.0 - SQL Injection
CVSS 7.5
CVE-2025-5252
HIGH
PHPGurukul News Portal Project 4.1 - SQL Injection via emailid Parameter
CVSS 7.3
CVE-2025-5251
HIGH
PHPGurukul News Portal Project 4.1 - SQL Injection via Category Parameter in edit-subcategory.php
CVSS 7.3
CVE-2025-5250
HIGH
PHPGurukul News Portal Project 4.1 - SQL Injection via Category Argument in Edit Category
CVSS 7.3
CVE-2025-5249
HIGH
PHPGurukul News Portal Project 4.1 - SQL Injection via Category Parameter in add-category.php
CVSS 7.3
CVE-2025-5248
HIGH
PHPGurukul Company Visitor Management System 1.0 - SQL Injection via fromdate/todate Parameter
CVSS 7.3
CVE-2025-5246
HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via adminremark Parameter
CVSS 7.3
CVE-2025-5232
MEDIUM
PHPGurukul Student Study Center Management System 1.0 - SQL Injection via Report Date Parameters
CVSS 4.7
CVE-2025-5231
HIGH
PHPGurukul Company Visitor Management System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-5230
HIGH
PHPGurukul Online Nurse Hiring System 1.0 - SQL Injection via fromdate/todate Argument
CVSS 7.3
CVE-2025-5229
HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via viewid Parameter
CVSS 7.3
CVE-2025-5227
HIGH
PHPGurukul Small CRM 3.0 - SQL Injection via aremark Parameter
CVSS 7.3
CVE-2025-5226
HIGH
PHPGurukul Small CRM 3.0 - SQL Injection via oldpass Parameter
CVSS 7.3
CVE-2025-5225
HIGH
Campcodes Advanced Online Voting System 1.0 - SQL Injection via Voter Parameter
CVSS 7.3
CVE-2025-5224
HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via Doctorspecialization Parameter
CVSS 7.3
CVE-2025-48743
MEDIUM
SIGB PMB < 8.0.1.2 - SQL Injection
CVSS 5.3
CVE-2025-5216
HIGH
PHPGurukul Student Record System 3.20 - SQL Injection via /login.php ID Parameter
CVSS 7.3
CVE-2025-5214
HIGH
Kashipara Responsive Online Learning Platform 1.0 - SQL Injection via ID Parameter
CVSS 7.3
CVE-2025-5213
HIGH
Responsive E-Learning System 1.0 - SQL Injection via /admin/delete_file.php ID Parameter
CVSS 7.3
Details
Vulnerabilities
19,618
Exploit Likelihood
High