CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,618 vulnerabilities with CWE-89
CVE-2025-48949 CRITICAL
navidrome 0.55.0-0.55.2 - SQL Injection via API Artist Endpoint Role Parameter
CVSS 9.8
CVE-2025-5359 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via ID Parameter in /appointment-history.php
CVSS 7.3
CVE-2025-5358 HIGH
PHPGurukul Cyber Cafe Management System 1.0 - SQL Injection via fromdate/todate Parameters
CVSS 7.3
CVE-2025-48912 MEDIUM
Apache Superset <4.1.2 - Privilege Escalation
CVSS 6.5
CVE-2025-5332 HIGH
1000 Projects Online Notice Board 1.0 - SQL Injection via Email Parameter
CVSS 7.3
CVE-2025-5298 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via fromdate/todate Parameter
CVSS 7.3
CVE-2025-5287 HIGH
Likes and Dislikes Plugin <1.0.0 - SQL Injection
CVSS 7.5
CVE-2025-5252 HIGH
PHPGurukul News Portal Project 4.1 - SQL Injection via emailid Parameter
CVSS 7.3
CVE-2025-5251 HIGH
PHPGurukul News Portal Project 4.1 - SQL Injection via Category Parameter in edit-subcategory.php
CVSS 7.3
CVE-2025-5250 HIGH
PHPGurukul News Portal Project 4.1 - SQL Injection via Category Argument in Edit Category
CVSS 7.3
CVE-2025-5249 HIGH
PHPGurukul News Portal Project 4.1 - SQL Injection via Category Parameter in add-category.php
CVSS 7.3
CVE-2025-5248 HIGH
PHPGurukul Company Visitor Management System 1.0 - SQL Injection via fromdate/todate Parameter
CVSS 7.3
CVE-2025-5246 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via adminremark Parameter
CVSS 7.3
CVE-2025-5232 MEDIUM
PHPGurukul Student Study Center Management System 1.0 - SQL Injection via Report Date Parameters
CVSS 4.7
CVE-2025-5231 HIGH
PHPGurukul Company Visitor Management System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-5230 HIGH
PHPGurukul Online Nurse Hiring System 1.0 - SQL Injection via fromdate/todate Argument
CVSS 7.3
CVE-2025-5229 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via viewid Parameter
CVSS 7.3
CVE-2025-5227 HIGH
PHPGurukul Small CRM 3.0 - SQL Injection via aremark Parameter
CVSS 7.3
CVE-2025-5226 HIGH
PHPGurukul Small CRM 3.0 - SQL Injection via oldpass Parameter
CVSS 7.3
CVE-2025-5225 HIGH
Campcodes Advanced Online Voting System 1.0 - SQL Injection via Voter Parameter
CVSS 7.3
CVE-2025-5224 HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via Doctorspecialization Parameter
CVSS 7.3
CVE-2025-48743 MEDIUM
SIGB PMB < 8.0.1.2 - SQL Injection
CVSS 5.3
CVE-2025-5216 HIGH
PHPGurukul Student Record System 3.20 - SQL Injection via /login.php ID Parameter
CVSS 7.3
CVE-2025-5214 HIGH
Kashipara Responsive Online Learning Platform 1.0 - SQL Injection via ID Parameter
CVSS 7.3
CVE-2025-5213 HIGH
Responsive E-Learning System 1.0 - SQL Injection via /admin/delete_file.php ID Parameter
CVSS 7.3
Details
Vulnerabilities 19,618
Exploit Likelihood High