CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,620 vulnerabilities with CWE-89
CVE-2025-47478
HIGH
Metagauss ProfileGrid <5.9.5.0 - SQL Injection
CVSS 8.5
CVE-2025-46539
CRITICAL
WPFable Fable Extra <1.0.6 - SQL Injection
CVSS 9.3
CVE-2025-46463
HIGH
Yamna Khawaja Mailing Group Listserv <3.0.4 - SQL Injection
CVSS 8.5
CVE-2025-46460
CRITICAL
Detheme Easy Guide <1.0.0 - SQL Injection
CVSS 9.3
CVE-2025-46455
CRITICAL
IndigoThemes WP HRM LITE - SQL Injection
CVSS 9.3
CVE-2025-41377
HIGH
Gandia Integra Total - SQL Injection
CVE-2025-39504
CRITICAL
Goodlayers Hotel <3.1.4 - SQL Injection
CVSS 9.3
CVE-2025-39501
CRITICAL
Goodlayers Hostel <3.1.2 - SQL Injection
CVSS 9.3
CVE-2025-31914
CRITICAL
kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder <1....
CVSS 9.3
CVE-2025-31397
CRITICAL
smartcms Bus Ticket Booking <1.7 - SQL Injection
CVSS 9.3
CVE-2025-31056
CRITICAL
Techspawn WhatsCart <1.1.0 - SQL Injection
CVSS 9.3
CVE-2025-41407
HIGH
ManageEngine ADAudit Plus < 8511 - SQL Injection in OU History Report
CVSS 8.3
CVE-2025-3893
HIGH
MegaBIP < 5.19 - Authenticated SQL Injection via Page Edit Reason Input
CVE-2025-36527
HIGH
ManageEngine ADAudit Plus < 8511 - SQL Injection via Report Export
CVSS 8.3
CVE-2025-48701
MEDIUM
openDCIM < 23.04 - SQL Injection in people_depts.php
CVSS 5.4
CVE-2025-5081
HIGH
Campcodes Cybercafe Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5079
HIGH
PHPGurukul/Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-32814
CRITICAL
NetMRI Unauthenticated SQL Injection via skipjackUsername
CVSS 9.8
CVE-2025-5078
HIGH
PHPGurukul/Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5077
HIGH
Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-41403
HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection
CVSS 8.3
CVE-2025-3836
HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Logon Events Aggregate Report
CVSS 8.3
CVE-2025-5057
HIGH
Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5056
HIGH
Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-3751
HIGH
TIBCO ActiveMatrix BusinessWorks 5.16.1-HF-01 - SQL Injection
Details
Vulnerabilities
19,620
Exploit Likelihood
High