CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,620 vulnerabilities with CWE-89
CVE-2025-47478 HIGH
Metagauss ProfileGrid <5.9.5.0 - SQL Injection
CVSS 8.5
CVE-2025-46539 CRITICAL
WPFable Fable Extra <1.0.6 - SQL Injection
CVSS 9.3
CVE-2025-46463 HIGH
Yamna Khawaja Mailing Group Listserv <3.0.4 - SQL Injection
CVSS 8.5
CVE-2025-46460 CRITICAL
Detheme Easy Guide <1.0.0 - SQL Injection
CVSS 9.3
CVE-2025-46455 CRITICAL
IndigoThemes WP HRM LITE - SQL Injection
CVSS 9.3
CVE-2025-41377 HIGH
Gandia Integra Total - SQL Injection
CVE-2025-39504 CRITICAL
Goodlayers Hotel <3.1.4 - SQL Injection
CVSS 9.3
CVE-2025-39501 CRITICAL
Goodlayers Hostel <3.1.2 - SQL Injection
CVSS 9.3
CVE-2025-31914 CRITICAL
kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder <1....
CVSS 9.3
CVE-2025-31397 CRITICAL
smartcms Bus Ticket Booking <1.7 - SQL Injection
CVSS 9.3
CVE-2025-31056 CRITICAL
Techspawn WhatsCart <1.1.0 - SQL Injection
CVSS 9.3
CVE-2025-41407 HIGH
ManageEngine ADAudit Plus < 8511 - SQL Injection in OU History Report
CVSS 8.3
CVE-2025-3893 HIGH
MegaBIP < 5.19 - Authenticated SQL Injection via Page Edit Reason Input
CVE-2025-36527 HIGH
ManageEngine ADAudit Plus < 8511 - SQL Injection via Report Export
CVSS 8.3
CVE-2025-48701 MEDIUM
openDCIM < 23.04 - SQL Injection in people_depts.php
CVSS 5.4
CVE-2025-5081 HIGH
Campcodes Cybercafe Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5079 HIGH
PHPGurukul/Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-32814 CRITICAL
NetMRI Unauthenticated SQL Injection via skipjackUsername
CVSS 9.8
CVE-2025-5078 HIGH
PHPGurukul/Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5077 HIGH
Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-41403 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection
CVSS 8.3
CVE-2025-3836 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Logon Events Aggregate Report
CVSS 8.3
CVE-2025-5057 HIGH
Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5056 HIGH
Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-3751 HIGH
TIBCO ActiveMatrix BusinessWorks 5.16.1-HF-01 - SQL Injection
Details
Vulnerabilities 19,620
Exploit Likelihood High