CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,620 vulnerabilities with CWE-89
CVE-2025-5032 HIGH
Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5008 HIGH
projectworlds Online Time Table Generator 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5006 HIGH
Campcodes Online Shopping Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5004 HIGH
projectworlds Online Time Table Generator 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5003 HIGH
projectworlds Online Time Table Generator 1.0 - SQL Injection
CVSS 7.3
CVE-2025-5002 HIGH
SourceCodester Client Database Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-26086 HIGH
RSI Queue Management System v3.0 - Unauthenticated Blind SQL Injection via TaskID Parameter
CVSS 7.5
CVE-2025-40635 CRITICAL
Comerzzia Backoffice: Sales Orchestrator 3.0.15 - SQL Injection
CVE-2025-39395 CRITICAL
mojoomla WPAMS <44.0 - SQL Injection
CVSS 9.3
CVE-2025-39389 CRITICAL
Solid Plugins AnalyticsWP <2.1.2 - SQL Injection
CVSS 9.3
CVE-2025-39386 CRITICAL
Mojoomla Hospital Management System <47.0 - SQL Injection
CVSS 9.3
CVE-2025-39357 HIGH
Mojoomla Hospital Management System <47.0 - SQL Injection
CVSS 8.5
CVE-2025-39355 HIGH
roninwp FAT Services Booking <5.6 - SQL Injection
CVSS 8.5
CVE-2025-32924 HIGH
roninwp Revy <= 2.1 - SQL Injection
CVSS 8.5
CVE-2025-39445 CRITICAL
Highwarden Super Store Finder <7.2 - SQL Injection
CVSS 9.3
CVE-2025-39403 HIGH
mojoomla WPAMS <44.0 - SQL Injection
CVSS 8.5
CVE-2025-43833 HIGH
Amir Helzer Absolute Links <1.1.1. - SQL Injection
CVSS 7.6
CVE-2025-4941 HIGH
PHPGurukul Credit Card Application Management System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-4940 HIGH
1000projects Daily College Class Work Report Book 1.0 - SQL Injection via batch Parameter in admin_info.php
CVSS 7.3
CVE-2025-39370 HIGH
Cnilsson iCafe <1.8.3 - SQL Injection
CVSS 7.6
CVE-2025-4938 MEDIUM
PHPGurukul Employee Record Management System 1.3 - SQL Injection via Email Parameter in registererms.php
CVSS 6.3
CVE-2025-4937 HIGH
Apartment Visitor Management System 1.0 - SQL Injection via Profile Mobile Number Parameter
CVSS 7.3
CVE-2025-4936 HIGH
projectworlds Online Food Ordering System 1.0 - SQL Injection via /admin-page.php 1_price Parameter
CVSS 7.3
CVE-2025-48280 HIGH
AutomatorWP <5.2.1.3 - SQL Injection
CVSS 7.6
CVE-2025-48278 HIGH
davidfcarr RSVPMarker <11.5.6 - SQL Injection
CVSS 8.5
Details
Vulnerabilities 19,620
Exploit Likelihood High